Access List not working correctly ASA 5520

Hi all,

We've had a network add and have two inline firewalls. On the second firewall it appears that our inbound access-list is not working.

To test we've currently got:

access-list inside_in extended deny ip any any log access-group inside_in in interface inside

The problem we have is that we can still ping the second firewall even though all IP traffic should be denied. Has anyone ever come across this, and if so, do they know of a fix?

We do have a second access-list called outside_in which is applied inbound on the outside interface. Could this cause a conflict?

Many thanks,

Chris

Reply to
Chris
Loading thread data ...

That's an outbound access-list, not an inbound access-list.

Pinging a PIX or ASA firewall is not controlled by access-group . Pinging a PIX or ASA firewall is controlled by the 'icmp' command.

Reply to
Walter Roberson

Sorry, I was implying it was inbound relative to the firewall. But yes, it is outbound.

First I knew of that.

Many thanks,

Chris

Reply to
Chris

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.