How to do a Pathping through Cisco ASA 5500

Posted on 2009-05-16
Last Modified: 2013-11-16
We had problems with our internet access and I was asked to do a ping, tracert, and parthping from my PC to the internet service provider to see what was droppoing packets.

I know how do to a ping or tracert on the ASA  appliance - but all attemtps to do a ping, tracert or pathping from my PC fialed as soon as it hit the ASA.

Could someone tell me what I need to do - I rtied creating a rule to let all icap traffic thorugh - but it still blocked the traffice.
Question by:Mawallace
LVL 13

Expert Comment

ID: 24404303
icmp permit any any Inside
class-map class-default
match any
policy-map global_policy
class class-default
set connection decrement-ttl
service-policy global_policy global
icmp unreachable rate-limit 10 burst-size 5
access-list outside_access_in permit icmp any any echo-reply
access-list outside_access_in permit icmp any any time-exceeded
access-list outside_access_in permit icmp any any destination-unreachable
access-list inside_access_in permit icmp any any echo
access-list inside_access_in permit icmp any any echo-reply
access-list inside_access_in permit icmp any any time-exceeded
access-list inside_access_in permit icmp any any destimatiom-unreachable
LVL 18

Accepted Solution

decoleur earned 500 total points
ID: 24425787
you don't need to do all that for ICMP support... the problem is that you need to add an icmp inspection to your global policy so it understands that ICMP type 0 is a response to ICMP type 8.

assuming you have a global policy add icmp to it:

conf t
policy-map global_policy
 class inspection_default
  inspect icmp
wri mem

hope this helps,


Author Closing Comment

ID: 31582280

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question