ASA Packet Tracer / Specify Destination Interface

Tim Ballin
Tim Ballin used Ask the Experts™
on
I'd like to test connectivity between a host in my DMZ and and a host on my inside network using the packet tracer function. However, although I can specify the source interface, I don't see any way to specify the destination interface.  Running the trace defaults to using the outside interface as the destination.  Can a destination interface be specified?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Network and Security consultant
Commented:
There is no support for specifying egress interface. The purpose of the packet-tracer command is to emulate an incoming packet and that is done in many different stages. One of these is the route lookup. The packet is in your case is sent to the outside interface because the route lookup decides that the destination ip is reachable via that interface according to the routing table.

So if the packet shouldnt be egressed on outside, that is probably the cause of your problem and you need to have a look at the routing table in the asa.

Best regards
Jimmy

Author

Commented:
Perfect - thanks!

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial