Cannot ping from DMZ to Inside of Cisco ASA
Posted on 2011-10-05
Below is the topology diagram on which i have question:
What is required
10.240.37.x LAN should be able to ping remote LAN 172.10.x
Points to note
172.10.x is NATd on the ASAFW as below -- 172.11.10.x ~ 172.10.10.x, ACL allows this traffic
What is happening
I can telnet from 10.240.37.x LAN to 172.10.10.x
What is not happening
i cannot ping from 172.10.10.x from 10.240.37.x LAN
ASA logs show that icmp connection is being built and torned down.
All upstream and return routes are correct in all the intermediate hops but still no icmp.
Any ideas, greatly appreciated.