Solved

The ping is successful at ASA ?

Posted on 2014-09-19
4
196 Views
Last Modified: 2014-10-03
Dear All

Here is a question. Can you give your answer to it ?

Topology:
e1-ASA-e0--------------e0/1-Router

Config:
ASA:
interface e0
ip address 12.1.1.1 255.255.255.0
outside
interface e1
ip address 10.1.1.1 255.255.255.0
inside

Router
interface e0/1
ip address 12.1.1.2 255.255.255.0
ip route 0.0.0.0 0.0.0.0 12.1.1.1

The question is, at ASA, command "ping inside 12.1.1.2" is succcessful? why ?
0
Comment
Question by:EESky
  • 2
  • 2
4 Comments
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 500 total points
ID: 40334168
Why would you want to ping the outside IP from the inside?

This is completely normal :)

screen grab
0
 

Author Comment

by:EESky
ID: 40334334
Thank you for your fast reply. The reason that i asked the question is that i am trying to setup vpn asa to asa. I did not attach PC to the inside of ASA. In order to initiate the vpn connection without attached PC, I want to use the command to replace ping from the PC. But the command ping inside x.x.x.x did not work at my ASA. I do not know why. that is why i want to know how the command works.
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 40334340
OK I see, first before you do anything make sure you have a default inspection map, and that map inspects ICMP like this;
Cisco Firewalls and PING

OK asuming you have that in place, if the lan on network A is 192.168.1.0/24 (and the firewall internal interface is 192.168.1.1). And NEtwork B is 192.168.2.0/24 (firewall inside interface is 192.168.2.1).

From the Firewall at Site A if you issue;

ping inside 192.168.2.1

(Assuming the tunnel is up and estalished) - the ping will fail - UNLESS both firewalls have the following command in their config;

management-access inside
0
 

Author Comment

by:EESky
ID: 40334349
Yes, you are right. the ping in this situation should not be successful
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Radius setup on a Cisco Switch with Server 2012 23 83
CCNA lab 6 37
Connecting a New Subnet to Network 4 29
Setting up NAT translation for RDP 6 19
Juniper VPN devices are a popular alternative to using Cisco products. Last year I needed to set up an international site-to-site VPN over the Internet, but the client had high security requirements -- FIPS 140. What and Why of FIPS 140 Federa…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question