43-5
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 43 Troubleshooting the Security Appliance
Testing Your Configuration
hostname(config-cmap)#
policy-map ICMP-POLICY
hostname(config-pmap)#
class ICMP-CLASS
hostname(config-pmap-c)#
inspect icmp
hostname(config-pmap-c)#
service-policy ICMP-POLICY global
Alternatively, you can also apply the ICMP access list to the destination interface to allow ICMP traffic
back through the security appliance.
Step 4
Ping from the host or router through the source interface to another host or router on another interface.
Repeat this step for as many interface pairs as you want to check.
If the ping succeeds, a system log message appears to confirm the address translation for routed mode
(305009 or 305011) and that an ICMP connection was established (302020). You can also enter either
the
show xlate
or
show conns
command to view this information.
If the ping fails for transparent mode, contact Cisco TAC.
For routed mode, the ping might fail because NAT is not configured correctly (see
Figure 43-5
). This
failure is more likely to occur if you enable NAT control. In this case, a system log message appears,
showing that the NAT failed (305005 or 305006). If the ping is from an outside host to an inside host,
and you do not have a static translation (required with NAT control), the following system log message
appears: “106010: deny inbound icmp.”
Note
The security appliance only shows ICMP debug messages for pings to the security appliance
interfaces, and not for pings through the security appliance to other hosts.
Figure 43-5
Ping Failure Because the Security Appliance is not Translating Addresses
Disabling the Test Configuration
After you complete your testing, disable the test configuration that allows ICMP to and through the
security appliance and that prints debug messages. If you leave this configuration in place, it can pose a
serious security risk. Debug messages also slow the security appliance performance.
To disable the test configuration, perform the following steps:
Step 1
To disable ICMP debug messages, enter the following command:
hostname(config)#
no debug icmp trace
Step 2
To disable logging, if desired, enter the following command:
hostname(config)#
no logging on
Step 3
To remove the ICMPACL access list, and delete the related
access-group
commands, enter the following
command:
hostname(config)#
no access-list ICMPACL
Ping
Router
Router
Host
Host
Security
Appliance
126694
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......