<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can not ping through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-not-ping-through-asa/m-p/3183920#M1066148</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Ping from higher security level to lower security level should work. The other way around may need acl.&lt;/P&gt;&lt;P&gt;&amp;nbsp;You are probably missing packet inspection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;policy-map global_policy
   class inspection_default
   inspect icmp&lt;/PRE&gt;</description>
    <pubDate>Thu, 14 Sep 2017 10:28:08 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2017-09-14T10:28:08Z</dc:date>
    <item>
      <title>Can not ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-not-ping-through-asa/m-p/3183892#M1066147</link>
      <description>&lt;P&gt;Hello, Here is diagram: R1 ---- ASA(Outside) ---- R2&lt;/P&gt;&lt;P&gt;ASA can ping R1 and R2 respectively, and both routers can ping ASA. But R1 cannot ping R2. Vlan1 connect to R1 and Vlan2 connect to R2. Anyone can help find something missing: Below is relevant configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5505:&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;BR /&gt;switchport access vlan 2&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.1.1.254 255.255.255.0&lt;BR /&gt;interface Vlan2&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 10.0.0.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list Outside-in extended permit icmp any any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-group Outside-in in interface outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Both routers have static route pointing at ASA&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:18:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-ping-through-asa/m-p/3183892#M1066147</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2020-02-21T14:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can not ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-not-ping-through-asa/m-p/3183920#M1066148</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Ping from higher security level to lower security level should work. The other way around may need acl.&lt;/P&gt;&lt;P&gt;&amp;nbsp;You are probably missing packet inspection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;policy-map global_policy
   class inspection_default
   inspect icmp&lt;/PRE&gt;</description>
      <pubDate>Thu, 14 Sep 2017 10:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-ping-through-asa/m-p/3183920#M1066148</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-09-14T10:28:08Z</dc:date>
    </item>
  </channel>
</rss>

