Re: PIX7.x/ASA and icmp redirects



In article <4445baab$1@xxxxxxxxxxxxxxxxxxxxx>,
Tosh <mbasc@xxxxxxxxxxxxx> wrote:
Anyone knows if cisco has added the capability of sending icmp redirects to
internal users in Pix7.x and asa appliances?

I'm not certain, but for the PIX at least, I would find it quite
unlikely. The PIX is designed not to allow packets to go back out
the same interface they came in on [*], and the RFC requirements that
go with support for ICMP Redirect require that the packet be
passed along (though the Redirect message itself need not always
be sent.)

[*] Exception: in PIX 7.x, there is an option to allow the
packet through provided that at least one component of the path
is a VPN tunnel... in which case it would never be the -same- packet
that went back out on the interface.
.



Relevant Pages

  • Re: [fw-wiz] full IPSEC tunnels on PIX and NAT ...
    ... For one thing, the PIX can not route out through the same interface, the ... packet comes into the device. ... if your VPNs terminate on the outside ...
    (Firewall-Wizards)
  • Re: ISA 2004 Routing
    ... goes from the interface where you receive the packet to the interface on ... your network where you want the packet to go. ... > connected to my PIX. ... > I have one NIC setup in the 192.168.1.0 subnet and another NIC setup on ...
    (microsoft.public.isaserver)
  • Re: [fw-wiz] Question about a Cisco PIX 515 - Routing question (I think)
    ... The PIX accepts the ... packet from the Internet, changes the addressing to map the ... It may be easier to get the servers ...
    (Firewall-Wizards)
  • Re: Connecting 2 networks via Win 2003 server
    ... The PIX will redirect the packet to ... (the RRAS router) because of the static route you added. ...
    (microsoft.public.win2000.ras_routing)
  • Re: Pix 501 Tunnelling problem
    ... You may also need to add the deny rule to your Crypto Access-List ... otherwise the PIX will still try to send the packets over the VPN. ... but the packet never exits the outside interface. ...
    (comp.dcom.sys.cisco)