Link to home
Start Free TrialLog in
Avatar of netcomp
netcomp

asked on

Can not ping anything on internet from behind Cisco ASA 5516

We have a cisco asa 5516 . We can not ping anything on the internet  . For example, if I ping google dns 8.8.8.8 , I will get a noreplay back  . I remember having this issue on another asa years ago . It had to do with ICMP. Anyway to fix it without being to unsure.  ? We have no issues accessing internet and all works. Just can't do ping tests.
Avatar of Dr. Klahn
Dr. Klahn

The firewall has been configured to reject ICMP Type 8 packets which are used for ping.

In general this is good practice; nearly all systems on a business LAN should not have a need to ping devices off their network.  It also prevents some "ping of death" attacks.
Avatar of netcomp

ASKER

well, we have switched to VOIP on cloud and are having some issued. The provider is saying its our issue and dropping packets .  They have givien us about 10 IP addresses that they want to make sure no packets are dropping packets for . So, I wanted to test them first by ping. We are not sure what is going on.
Pinging will never work unless you have icmp inspection turned on on the firewall.

did you configured policy from inside to outside permitting icmp ?

#access-list GLOBAL extended permit icmp object INSIDE_NET object OUTSIDE_NET


Avatar of netcomp

ASKER

They just asked for sip alg to turn off , but not sure how to do that on asa commend  line on ASA.

sip something different than ping , so you need to be sure that ips are pingable before playing with sip , sip may affect on jitter on call , call echo , one way call it mean you can call the phone and you can hear your neighbor , but neighbor can't hear you ...etc 

look at cisco asa configuration for " inspect sip "

and try to disable it using below command



#policy-map global_policy

 class inspection_default

  no inspect sip


This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.