troubleshooting Question

ASA ICMP traversing interfaces on 8.04

Avatar of neoponder
neoponder asked on
Software Firewalls
1 Comment1 Solution824 ViewsLast Modified:
Config:
ASA 5510 8.0.4 using:
1 physical outside interface
1 physical interface with 9 DMZ/Inside interfaces.
Useing no nat control, no statics

Issue:
I can ping the outside interface of the ASA.

From outside host, I want to ping VDMZ ASA interface. I can ping outside interface.  
(We want a vendor that has access only to their Subnet via L2L VPN to be able to monitor the ASA interface with ICMP.)
***
Vendor can ping all the equipment in their network accept ASA interface.
They use our ASA as their DF.
The virtual intefaces is trunked to a 2950 or 2960 depending on site, and all have the proper 802.1q tags defined.  except the unused native vlan1.
All interfaces have icmp any any acl
****
Is this a state table issue? Would static nat resolved this? or should it just work?


Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 1 Comment.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 1 Comment.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros