<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing failed to locate next hop for ICMP Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719510#M1049739</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;No nat, I can ping from the outside interface of the inside firewall =.2 to the internet facing firewall inside interface =.1 these are on same subnet connected to 3850, but i cannot ping from inside firewall beyond .2 of internet firewall, and i cannot ping from internet facing firewall .2 through to public address on outside interface of internet facing firewall, i have a default route poing outside interface any any, when i try putting a route on inside firewall pointing to .2 it says its a connected interface. what routes are needed and where please.?? could it be because the firewalls have an interface in same subnet.??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 04 Oct 2018 19:12:24 GMT</pubDate>
    <dc:creator>benolyndav</dc:creator>
    <dc:date>2018-10-04T19:12:24Z</dc:date>
    <item>
      <title>Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719482#M1049683</link>
      <description>&lt;P&gt;Please see attached document cant ping through firewall in DMZ with two ASA's&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719482#M1049683</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2020-02-21T16:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719491#M1049699</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Ping/ICMP is blocked on ASA by default. Try this:-&lt;BR /&gt;&lt;BR /&gt;ASA(config)# &lt;EM&gt;&lt;STRONG&gt;policy-map global_policy&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;ASA(config-pmap)# &lt;EM&gt;&lt;STRONG&gt;class default-inspection-class&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;ASA(config-pmap-c)# &lt;EM&gt;&lt;STRONG&gt;inspect icmp&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;BR /&gt;ASA(config)#&lt;EM&gt;&lt;STRONG&gt; fixup protocol icmp&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 18:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719491#M1049699</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-10-04T18:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719497#M1049707</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Already added to both Firewalls, any more ideas.??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 18:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719497#M1049707</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2018-10-04T18:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719504#M1049723</link>
      <description>Without seeing your configuration of all devices it's a bit hard. You said you cannot ping beyond .2 - do the devices beyond .2 have a route back to the source network you were pinging from? Are you natting anywhere?</description>
      <pubDate>Thu, 04 Oct 2018 19:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719504#M1049723</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-10-04T19:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719510#M1049739</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;No nat, I can ping from the outside interface of the inside firewall =.2 to the internet facing firewall inside interface =.1 these are on same subnet connected to 3850, but i cannot ping from inside firewall beyond .2 of internet firewall, and i cannot ping from internet facing firewall .2 through to public address on outside interface of internet facing firewall, i have a default route poing outside interface any any, when i try putting a route on inside firewall pointing to .2 it says its a connected interface. what routes are needed and where please.?? could it be because the firewalls have an interface in same subnet.??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 19:12:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719510#M1049739</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2018-10-04T19:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719512#M1049751</link>
      <description>Can you provide the full configuration of the firewalls and switches, indicating which firewall and switch relates to what in the diagram? Thanks</description>
      <pubDate>Thu, 04 Oct 2018 19:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719512#M1049751</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-10-04T19:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719519#M1049783</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I cant provide config yet but have done another doc see attachment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 19:35:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719519#M1049783</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2018-10-04T19:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719549#M1049791</link>
      <description>Ok, if you are pinging the internet from 172.20.57.2 and it fails, it would if you don't have nat configured. You'd need to nat traffic on the inside of the firewall behind the outside interface.</description>
      <pubDate>Thu, 04 Oct 2018 20:20:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719549#M1049791</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-10-04T20:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719554#M1049794</link>
      <description>&lt;P&gt;Hi Thanks for that,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so nat inside traffic to outside interface, any thoughts on traffic coming from inside firewall 172.20.57.1 to internet because that also fails.??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 20:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719554#M1049794</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2018-10-04T20:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719562#M1049870</link>
      <description>You would nat all networks (all networks that need to route through the internet firewall to access the internet) behind the internet firewall's outside interface, that would enable internet access.&lt;BR /&gt;&lt;BR /&gt;You need to ensure that the internet firewall has routes to the other networks and the inside firewall has a default route to the internet firewall. e.g route outside 0 0 172.20.57.2 &lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Thu, 04 Oct 2018 20:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719562#M1049870</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-10-04T20:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719566#M1049872</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Its not letting me add this&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;route outside 0 0 172.20.57.2&amp;nbsp; it says its a connected network.??&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 20:46:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719566#M1049872</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2018-10-04T20:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Routing failed to locate next hop for ICMP Firewall</title>
      <link>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719579#M1049874</link>
      <description>Well the next hop IP address needs to be connected, I don't see why you'd get this error. Can you provide the full configuration and a screenshot of the exact error when you add this to the inside firewall.</description>
      <pubDate>Thu, 04 Oct 2018 20:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-failed-to-locate-next-hop-for-icmp-firewall/m-p/3719579#M1049874</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-10-04T20:58:35Z</dc:date>
    </item>
  </channel>
</rss>

