jiggin23
asked on
Create Test DMZ and vlan
We have a 6509 at our core and an ASA 5520 as our edge firewall. I am trying to test something and created a new zone in the firewall, with an IP address of 172.19.1.1/24 . I put a box conneted to a 4500 switch with an IP of 172.19.1.2/24. I also created a new Vlan(65) and assigned it to the port that the .2 box is connected to, so it looks like this
Prod1--172.19.1.2
|
Core1
|
ASA5520--172.19.1.1
the new zone has a security level of 90. the vlan propogated to both switches okay, but I can not ping the .1 address from the .2 box. Do I need a route somewhere, we already us eigrp on the network.
Prod1--172.19.1.2
|
Core1
|
ASA5520--172.19.1.1
the new zone has a security level of 90. the vlan propogated to both switches okay, but I can not ping the .1 address from the .2 box. Do I need a route somewhere, we already us eigrp on the network.
ASKER
yes i have allowed icmp through the firewall from the new zone, i have an ip any to any and icmp any to any rule on that interface
If you debug it can you see the traffic - this will tell you if the problem is with the ASA or before / after it.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Forgot to trunk the new vlan to the core, thanks.
You could try debuging ICMP from the firewall and see if it is reaching the ASA or not.
#debug icmp trace