Avatar of leblanc
leblanc
 asked on

can only ping one way

I have a simple setup (see below) and I can only ping from siteA to siteB and not vice versa. Any thoughts will be greatly appreciated.

diagram
RoutersNetwork AnalysisNetworking

Avatar of undefined
Last Comment
skullnobrains

8/22/2022 - Mon
chaau

Can you check that ICMP protocol is not disabled on SiteA
Rafael

Can you show me your config for Site B and the 2811 router. Have you checked CDP?
leblanc

ASKER
siteB can see the Internet router via CDP. NOt sure how to check if icmp is diable on siteA. But SiteB cannot even ping the Internet router. I am using GNS3 as my lab test.

siteB config (very basic):
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname siteB
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
no ip domain lookup
!
multilink bundle-name authenticated
!
archive
 log config
  hidekeys
! 
ip tcp synwait-time 5
!
interface FastEthernet0/0
 no ip address
 shutdown
 duplex auto
 speed auto
!
interface FastEthernet0/1
 ip address 20.20.20.1 255.255.255.252 secondary
 ip address 30.30.30.1 255.255.255.240
 duplex auto
 speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 20.20.20.2
!
!
no ip http server
no ip http secure-server
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

Open in new window

I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
ASKER CERTIFIED SOLUTION
Don Johnston

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
leblanc

ASKER
This is just a lab so I have 3 routers with nothing on it, just the IP addresses for the interfaces and the default route on siteA and siteB. I agree with you, if siteA can ping siteB then that means siteB has a route back to siteA. That is why I do not understand why siteB cannot ping siteA. I am pinging from router to router.
SiteB router cannot even ping fa0/1 of the Internet router.
Could it be a bug from my GNS3? I am not sure because I rebuilt my lab several times already.
Don Johnston

Post the configs of the three routers please.
leblanc

ASKER
The Internet router:
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname internet
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
no ip domain lookup
!
multilink bundle-name authenticated

ip tcp synwait-time 5
!
!
!
interface FastEthernet0/0
 ip address 10.10.10.2 255.255.255.240
 duplex auto
 speed auto
!
interface FastEthernet0/1
 ip address 20.20.20.2 255.255.255.252
 duplex auto
 speed auto
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!

control-plane
!!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

Open in new window


SiteA router:
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SiteA
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
multilink bundle-name authenticated
!
ip tcp synwait-time 5
!

interface FastEthernet0/0
 ip address 10.10.10.1 255.255.255.240
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 10.10.10.2
!
!
no ip http server
no ip http secure-server
!
!!
control-plane
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

Open in new window


You can find ID: 40060669
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Don Johnston

There's nothing in the configs that would cause this. Emulators and simulators sometimes don't behave as expected.

You could try making the 20.20.20.1 address on Site B the only address on that interface.
leblanc

ASKER
Yes. That will work. But I was trying to duplicate a production environment and it has a secondary IP address on fa0/0 on siteB. I need to look into more detail. Thx
SOLUTION
Don Johnston

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Akinsd

Check the computer you are trying to ping.
Access the firewall (firewall.cpl)
Access "Allow a program or feature through windows firewall"
Check if "file and printer sharing" is enabled.

If you can ping from one side, then icmp traffic is not blocked any where.
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
Don Johnston

This is ping is router-to-router. There is no PC.
skullnobrains

my guess would be that pings are emitted from 30.30.30.1 address and neither of the other routers have a route to this address. if that is correct you should be able to sniff/trace the pings (echo but not reply) on the other routers.

you shold also be able to get the pings to work by specifying the secondary address as the source address of the pings
SOLUTION
Rafael

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
skullnobrains

on the internet router

ip route 30.30.30.1 255.255.255.240 20.20.20.1

my previous post was wrong : siteA has a default gateway which is good enough
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.