Link to home
Start Free TrialLog in
Avatar of jiggin23
jiggin23

asked on

Create Test DMZ and vlan

We have a 6509 at our core and an ASA 5520 as our edge firewall.  I am trying to test something and created a new zone in the firewall, with an IP address of 172.19.1.1/24 .  I put a box conneted to a 4500 switch with an IP of 172.19.1.2/24.  I also created a new Vlan(65) and assigned it to the port that the .2 box is connected to, so it looks like this

Prod1--172.19.1.2
 |
Core1
 |
ASA5520--172.19.1.1

the new zone has a security level of 90.  the vlan propogated to both switches okay, but I can not ping the .1 address from the .2 box.  Do I need a route somewhere, we already us eigrp on the network.
Avatar of H_Harry
H_Harry

Have you allowed ICMP through the ASA via an ACL?
 
You could try debuging ICMP from the firewall and see if it is reaching the ASA or not.
 
#debug icmp trace
 
 
Avatar of jiggin23

ASKER

yes i have allowed icmp through the firewall from the new zone, i have an ip any to any and icmp any to any rule on that interface
If you debug it can you see the traffic - this will tell you if the problem is with the ASA or before / after it.
ASKER CERTIFIED SOLUTION
Avatar of kdearing
kdearing
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Forgot to trunk the new vlan to the core, thanks.