Enable Outbound ICMP on Cisco ASA 9.9

Scenario:

I set up a Cisco ASAv  5525 and placed a Windows VM behind it. I created the NAT (PAT) policy and default route. The Cisco ASA could ping external IP addresses (eg 8.8.8.8). However, the VM behind that could not ping any external IP addresses despite being able to ping the Cisco ASA.

 

Windows VM: 192.168.2.200

Cisco ASA: 192.168.2.100

 

Resolution

On the Cisco ASA use the following command

fixup protocol icmp

cisco_asa