Solved

Blocking All Incoming ICMP Traffic With Cisco ASA 5510

Posted on 2010-11-16
4
1,021 Views
Last Modified: 2012-05-10
This is a fairly simple question and i'm sure there is a fairly simple answer but for whatever reason I can't seem to get ICMP blocked properly on my external interface of my ASA.  I obviously don't want my external interface to be pingable but no matter what i configure in the ACL I am still able to ping the outside IP from outside of our network.
 
external ip is xxx.xxx.xxx.178.
 
What is the easiest, best practice way to accomplish this?
0
Comment
Question by:gedruspax
  • 2
  • 2
4 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 250 total points
Comment Utility
ICMP to and from the ASA itself is not controlled via the interface access-lists.

Use the following:

conf t
icmp deny any outside
0
 

Author Comment

by:gedruspax
Comment Utility
our outside interface is actually named Outside_INF

so would the command be

conf t
icmp deny any Outside_INF?
0
 
LVL 43

Expert Comment

by:JFrederick29
Comment Utility
Yeah, exactly.
0
 

Author Comment

by:gedruspax
Comment Utility
Yup, that worked, thanks so much for your help!
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now