<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5520 Firewall configuration Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-configuration-problem/m-p/764649#M1006807</link>
    <description>&lt;P&gt;I have an ASA 5520 placed between two different networks and have to provide interconnectivity between them. The ASA is placed between two Layer 3 switches. I had configured ASA as below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0  //(Outside)&lt;/P&gt;&lt;P&gt;nameif Network-2 &lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 10.66.88.100 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1  //(Inside)&lt;/P&gt;&lt;P&gt;nameif Network-1&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.68.1.7 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Network-2) 1 10.66.0.0 netmask 255.255.0.0&lt;/P&gt;&lt;P&gt;nat (Network-1) 1 10.68.1.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route Network-2  10.66.1.0 255.255.255.0 10.66.88.200 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: &lt;/P&gt;&lt;P&gt;1.) Say the two different networks are 10.68.1.0 (network A)  and 10.66.1.0 (network B)&lt;/P&gt;&lt;P&gt;2.) 10.66.88.200 is the next hop ip address of the layer3 switch at Network-B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to ping all the systems in the two networks from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am unable to ping interface 10.66.88.100 from Network-A and Network B. How to resolve the problem?? Please guide?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All helpful posts will be rated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;Sridhar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:01:51 GMT</pubDate>
    <dc:creator>sridharpoola</dc:creator>
    <dc:date>2019-03-11T10:01:51Z</dc:date>
    <item>
      <title>ASA 5520 Firewall configuration Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-configuration-problem/m-p/764649#M1006807</link>
      <description>&lt;P&gt;I have an ASA 5520 placed between two different networks and have to provide interconnectivity between them. The ASA is placed between two Layer 3 switches. I had configured ASA as below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0  //(Outside)&lt;/P&gt;&lt;P&gt;nameif Network-2 &lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 10.66.88.100 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1  //(Inside)&lt;/P&gt;&lt;P&gt;nameif Network-1&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.68.1.7 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Network-2) 1 10.66.0.0 netmask 255.255.0.0&lt;/P&gt;&lt;P&gt;nat (Network-1) 1 10.68.1.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route Network-2  10.66.1.0 255.255.255.0 10.66.88.200 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: &lt;/P&gt;&lt;P&gt;1.) Say the two different networks are 10.68.1.0 (network A)  and 10.66.1.0 (network B)&lt;/P&gt;&lt;P&gt;2.) 10.66.88.200 is the next hop ip address of the layer3 switch at Network-B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to ping all the systems in the two networks from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am unable to ping interface 10.66.88.100 from Network-A and Network B. How to resolve the problem?? Please guide?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All helpful posts will be rated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;Sridhar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-configuration-problem/m-p/764649#M1006807</guid>
      <dc:creator>sridharpoola</dc:creator>
      <dc:date>2019-03-11T10:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Firewall configuration Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-firewall-configuration-problem/m-p/764650#M1006809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To allow network B to ping the outside interface try adding this to config &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)# icmp permit 10.66.1.0 255.255.255.0 outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't believe that the ASA device allows you to ping an interface that is remote ie. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from the inside you can only ping the inside interface of the ASA,, you cannot ping the outside interface and vice-versa. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2007 11:06:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-firewall-configuration-problem/m-p/764650#M1006809</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-04-19T11:06:50Z</dc:date>
    </item>
  </channel>
</rss>

