Solved

ASA to ASA site to site VPN. Cannot ping workstations, can ping printers!

Posted on 2014-11-11
3
155 Views
Last Modified: 2014-12-06
Site-A to Site-B VPN connection.

From Site-A to Site-B, I am able to ping Printers, and the ASA itself. No workstations are able to be pinged.

packet-tracer input inside icmp "Site-A" 8 0 "Site-B" detailed  , flow is denied by configured rule
ping inside "Site-B" , success 100%.

I can ping any of the printers at site b, or the ASA itself, but no workstations! Is this configuration in the one of the ASA's causing this?
0
Comment
Question by:paulrausch
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 10

Accepted Solution

by:
Ray earned 250 total points
ID: 40436003
Because I am a simple person, I'll ask the simple question:  Are the workstations running a firewall such as windows firewall?
0
 
LVL 7

Assisted Solution

by:tolinrome
tolinrome earned 250 total points
ID: 40464816
Hi paulrausch,
"flow is denied by configured rule" - it could be that the workstations are on a different ip range or subnet not in the ACL defined and the printers are and thats why they are not pingable. Please post the config if you can so we can take a look deeper into it.
0
 
LVL 2

Author Closing Comment

by:paulrausch
ID: 40485069
This project was terminated by the End User. Points awarded for attempts.
0

Featured Post

Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question