Internet access denied on L2 switch

Posted on 2009-04-28
Last Modified: 2012-05-06
Hi Expert
Please help!

Unable to ping public IP or ASA inside IP on Catalyst 2950 switch as an access level

My network topology is very simple.
Internet == Cisco 877 == Cisco ASA 5505 == Cat3750 == Cat2950

In L3 switch Cat3750 using console, I can ASA 5505 inside IP. In L2 switch Cat2950 using console, I CANNOT ping it.

ASA running with only default configuration and default access-list, no 1-to-1 NAT, no password is set. Already ICMP enabled in outside interface.
Cat3750 routed port is
Cat3750 trunk with Cat2950

Is anyone encounter? What is wrong?

Question by:chekfu
    LVL 21

    Expert Comment

    do you have a gateway set on 2950?
    does asa has an ip route to 2950 (if 2950 is connected via a routed port, then asa should have a static route to subnet)
    LVL 1

    Author Comment

    Cat3750 running IP in vlan20 as a management vlan
    Cat2950 running IP in vlan20, default-gateway is

    I tried one WinXP machine conneccted to Cat2950's port 5 as vlan100. VLAN100 interface IP
    WinXP IP parameter I manually configured: IP-, SM-, GW-, DNS-own ISP DNS. Using telnet in this machine, I can ping gateway which is Ping management vlan IPs or OK. Ping routed port OK. But ping (ASA inside IP) failed.

    What do you by Static route? What must I configure in my ASA? My ASA has only one static route which is  in outside interface.
    LVL 21

    Accepted Solution

    I suppose your ASA should have static route to cisco 3750

    I'm not very clearly understand your IP addressing, but if it is like this:

    <ASA[]>----<[]c3750[]>----<2950>---<PC with an IP of and GW to>

    then static route for ASA would look like:
    ip route

    so we effectively tell ASA, that there is one more subnet within our network, which is located behind c3750.

    In fact you can have several subnets behind c3750 and if you want all of them to be visible from ASA, then you should add static routes to all those networks.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
    Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
    This video is in connection to the article "The case of a missing mobile phone (". It will help one to understand clearly the steps to track a lost android phone.
    Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    15 Experts available now in Live!

    Get 1:1 Help Now