[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

Allow IP from across the WAN to pass through Cisco ASA 5505

Asked by danbrown1888 in Cisco PIX Firewall, Internet Control Message Protocol (ICMP)

Tags: Cisco ASA 5505, Ping from different network on internal nic

Hello. To start off I am very new to Cisco. I'm not clear on all the lingo, but have been putting in 1+ hours a day trying to learn. Everyone's help here has been great.

I have 6 offices and they are connected via MPLS. I can ping back and forth without a problem between all routers and workstations; except to a Cisco ASA 5505.

At our main office we have an ASA5505 with it's own dedicated Verizon FIOS for backups. It is connected via VPN to another site that has a ASA5505 where are backups are stored. When I ping from across the MPLS the ASA doesn't accept the ping. What can I do so it accepts the ping?

Setup: Ping from 192.168.100.X to 10.35.209.5 fails
Ping goes out of remote site Alpha DMZ 192.168.100.x, to the  site Alpha router 10.35.48.X, goes across the MPLS network, comes in the main office router with network range10.35.208.X to 10.35.209.x. From there it trys to ping 10.35.209.5 which is our ASA (this is not the main router for the location, but rather plugged into the switch off the main router). From any IP in the range of 10.35.208.X to 10.35.209.X I can ping the ASA at 10.35.209.5.

It seems the internal interface of 10.35.209.5 on the ASA is only allowed to accept connections from 10.35.208.x to 10.35.209.x. I would like it to also accept packets coming across the MPLS nework on the internal interface.

I did attach a Word Doc that contains the Syslog from the ASA5505 showing what happens when I try to ping from across the MPLS WAN to the internal interface of 10.35.209.5

Thank you!
 How would I resolve this issue?
Attachments:
 
Ping Log on Cisco ASA 5505
 
[+][-]10/31/09 11:22 AM, ID: 25710881Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]11/01/09 06:51 PM, ID: 25716802Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]11/03/09 05:44 AM, ID: 25728803Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]11/06/09 02:58 PM, ID: 25763812Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091021-EE-VQP-81 - Hierarchy / EE_QW_3_20080625