Solved

ASA to ASA site to site VPN. Cannot ping workstations, can ping printers!

Posted on 2014-11-11
3
148 Views
Last Modified: 2014-12-06
Site-A to Site-B VPN connection.

From Site-A to Site-B, I am able to ping Printers, and the ASA itself. No workstations are able to be pinged.

packet-tracer input inside icmp "Site-A" 8 0 "Site-B" detailed  , flow is denied by configured rule
ping inside "Site-B" , success 100%.

I can ping any of the printers at site b, or the ASA itself, but no workstations! Is this configuration in the one of the ASA's causing this?
0
Comment
Question by:paulrausch
3 Comments
 
LVL 10

Accepted Solution

by:
Ray earned 250 total points
ID: 40436003
Because I am a simple person, I'll ask the simple question:  Are the workstations running a firewall such as windows firewall?
0
 
LVL 7

Assisted Solution

by:tolinrome
tolinrome earned 250 total points
ID: 40464816
Hi paulrausch,
"flow is denied by configured rule" - it could be that the workstations are on a different ip range or subnet not in the ACL defined and the printers are and thats why they are not pingable. Please post the config if you can so we can take a look deeper into it.
0
 
LVL 2

Author Closing Comment

by:paulrausch
ID: 40485069
This project was terminated by the End User. Points awarded for attempts.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Juniper VPN devices are a popular alternative to using Cisco products. Last year I needed to set up an international site-to-site VPN over the Internet, but the client had high security requirements -- FIPS 140. What and Why of FIPS 140 Federa…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now