Cannot Ping across ASA 5510 from Server 2008 - FIREWALL IS OFF
Posted on 2010-08-18
I've got a strange one...
I have what can be described as a DMZ that is seperated from our main network by a Cisco ASA 5510. Now, here's one strange item...this DMZ area is the *inside* and more secure. Main network is the outside interface. Inside has security of 100, outside=0.
I have several Server 2003 machines in this DMZ. I have the proper firewall rules to allow pings to and from both directions and this works as desired with all the 2003 boxes. I've added my first Server 2008 box into this segment, compatible IP address. It can see/ping all servers within the DMZ...but cannot ping across the ASA to anything in our main network as the 2003 boxes can.
The gateway for this segment is NOT via the ASA. There is a router that provides the gateway. Keep in mind...static routes are already in place for our main network through the ASA...and this works fine for all the 2003 boxes. I've simply added a new IP address into the mix. It doesn't work and the only glaring difference is that this is a Server 2008 box!
Before you ask... the Windows Firewall is OFF and the service is stopped on the 2008 box.
IPv6 is disabled.
Due to PCI requirements, I cannot post an ASA config here...sorry. All I'm after is a pointer in the right direction as to why a Server 2008 box might behave differently from a 2003 box. Of course, if there's something else that might cause this, I'm all ears! Any ideas?