By extending the default inspection policy to include ICMP and ICMP errors, it is possible for users of a VPN to send a ping through an IPSec tunnel and also receive a response (echo).

Example configuration

policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
inspect icmp
inspect icmp error