Solved

How to do a Pathping through Cisco ASA 5500

Posted on 2009-05-16
3
1,509 Views
Last Modified: 2013-11-16
We had problems with our internet access and I was asked to do a ping, tracert, and parthping from my PC to the internet service provider to see what was droppoing packets.

I know how do to a ping or tracert on the ASA  appliance - but all attemtps to do a ping, tracert or pathping from my PC fialed as soon as it hit the ASA.

Could someone tell me what I need to do - I rtied creating a rule to let all icap traffic thorugh - but it still blocked the traffice.
0
Comment
Question by:Mawallace
3 Comments
 
LVL 13

Expert Comment

by:Quori
ID: 24404303
icmp permit any any Inside
class-map class-default
match any
policy-map global_policy
class class-default
set connection decrement-ttl
exit
exit
service-policy global_policy global
icmp unreachable rate-limit 10 burst-size 5
access-list outside_access_in permit icmp any any echo-reply
access-list outside_access_in permit icmp any any time-exceeded
access-list outside_access_in permit icmp any any destination-unreachable
access-list inside_access_in permit icmp any any echo
access-list inside_access_in permit icmp any any echo-reply
access-list inside_access_in permit icmp any any time-exceeded
access-list inside_access_in permit icmp any any destimatiom-unreachable
0
 
LVL 18

Accepted Solution

by:
decoleur earned 500 total points
ID: 24425787
you don't need to do all that for ICMP support... the problem is that you need to add an icmp inspection to your global policy so it understands that ICMP type 0 is a response to ICMP type 8.

assuming you have a global policy add icmp to it:

conf t
policy-map global_policy
 class inspection_default
  inspect icmp
end
wri mem

hope this helps,

-t
0
 

Author Closing Comment

by:Mawallace
ID: 31582280
none
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now