YFZblu wrote: » Yes, the ASA should be facilitating inspection as the default behavior, allowing the return traffic. Do you have ACL's applied anywhere? My understanding is that an ACL will completely override the default behavior. My suggestion at this point is checking syslog messages; the ASA should log dropped packets and give you more details.
cisco_trooper wrote: » Make sure you are actually inspecting ICMP...very important.
YFZblu wrote: » Am I the only person slightly annoyed that the ASA CLI syntax differs from routers?