Question { 9330 }
How ICMP is used in ping and traceroute facilities
Answer
Internet Control Message Protocol (ICMP) pings and
traceroute on the PIX Firewall are handled differently
based on the version of PIX and ASA code.
Inbound ICMP through the PIX/ASA is denied by default.
Outbound ICMP is permitted, but the incoming reply is
denied by default.
** ASA/PIX does not support ICMP redirects, because it does
not support asymmetric routing