Solved

ASA allowing/dropping ICMP unreachable?

Posted on 2013-10-23
3
747 Views
Last Modified: 2013-10-24
I am tracking down an issue where a router need o fragment a packet but the DF is set. The router sends an ICMP unreachable message need to fragment but df set. I created a capture on the ASA firewall to see if the ICMP packed it alloed through or dropped.

Capture capin int inside match icmp any any
Capture capout outside match icmp any any


the following is captured and displayed when I do a show capture capin:

1871: 23:01:20.632306       172.25.251.46 > 91.216.63.241: icmp: 172.12.18.218 unreachable - need to frag (mtu 1420)

How can I see if the Firewall is allowing this ICMP or dropping it? I would like to know what is happening with it.

Thanks
0
Comment
Question by:troubleshooter141
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 18

Accepted Solution

by:
fgasimzade earned 250 total points
ID: 39596425
You can just check the logs in ASDM
0
 
LVL 18

Assisted Solution

by:Akinsd
Akinsd earned 250 total points
ID: 39597370
packet-tracer input inside icmp 172.12.18.218 8 0 91.216.63.241 detailed

Then check the result of each phase if dropped or allowed
eg

Phase: 13
Type: IP-OPTIONS
Subtype:
Result: ALLOW

Result:
input-interface: inside
input-status: up
input-line-status: up
output-interface: sonicnet
output-status: up
output-line-status: up
Action: allow
0
 
LVL 3

Author Closing Comment

by:troubleshooter141
ID: 39597916
Thank you. I ended up creating a capture filter for dropped ASP and this gave me what I needed.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
With the rising number of cyber attacks in recent years, keeping your personal data safe has become more important than ever. The tips outlined in this article will help you keep your identitfy safe.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question