<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't ping ASA from end device via IPSEC Tunnel in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594634#M1089305</link>
    <description>&lt;P&gt;NAT exception must include traffic for both.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;do you run packet tracer ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;packet-tracer input &lt;STRONG&gt;Inside&lt;/STRONG&gt;&amp;nbsp;icmp&amp;nbsp;ASA 8 0 Site-C detailed&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Apr 2022 16:35:16 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-04-18T16:35:16Z</dc:date>
    <item>
      <title>Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594546#M1089294</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 3 sites, A, B, and C.&amp;nbsp;&lt;/P&gt;&lt;P&gt;A - Would be the HUB.&lt;/P&gt;&lt;P&gt;B - Spoke - Working&lt;/P&gt;&lt;P&gt;C - Spoke - Not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From site A end device I can ping the ASA from site B, but I can't ping site C even with the same configs and tunnels are up I still can't ping ASA site C. I can confirm that behind the ASA - C end devices is reachable, only the ASA is not.&lt;BR /&gt;&lt;BR /&gt;I already enabled inspect ICMP added ACL for ICMP made sure interesting traffic is passing thru and UN-NAT is in place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 14:54:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594546#M1089294</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-18T14:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594548#M1089295</link>
      <description>&lt;P&gt;same IPSec tunnel I mention before that there is issue with it or this new IPSec tunnel ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 14:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594548#M1089295</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-18T14:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594559#M1089296</link>
      <description>&lt;P&gt;different one sir. need some help tshooting this.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 15:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594559#M1089296</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-18T15:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594564#M1089297</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1254272"&gt;@baroncse&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;I can confirm that behind the ASA - C end devices is reachable, only the ASA is not.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;so are you actually just trying to ping the ASA C's inside interface over the VPN tunnel?&lt;/P&gt;
&lt;P&gt;If so use the command "management-access &amp;lt;inside interface&amp;gt;" to permit that traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure you ping from a device behind ASA A not from the ASA itself.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 15:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594564#M1089297</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-18T15:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594570#M1089298</link>
      <description>&lt;P&gt;sorry forgot to mention I also have this configured as well "management-access inside"&lt;/P&gt;&lt;P&gt;And yes from site A end device going to site C ASA no pings. but from site A end device going to site B ASA working perfectly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C and B have the same configs for the tunnel going to site A.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 15:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594570#M1089298</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-18T15:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594572#M1089299</link>
      <description>&lt;P&gt;&lt;SPAN&gt;A - Would be the HUB&amp;lt;- issue here&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I think you config&amp;nbsp;ONE Policy ACL with two line for both spoke??&lt;BR /&gt;that wrong&amp;nbsp;&lt;BR /&gt;config two&amp;nbsp;policy ACL one for each Spoke.&lt;BR /&gt;&lt;BR /&gt;and two tunnel one for each Spoke.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 15:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594572#M1089299</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-18T15:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594591#M1089301</link>
      <description>&lt;P&gt;they have separate configs for ACL and Tunnels. Lets just say spoke to spoke (A to C) for the tunnels.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can confirm tunnel is up because from A end device to C end device they have connectivity I can RDP and ICMP, but the ASA - C is the only issue. I need the ASA - C be pingable from A end device.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 15:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594591#M1089301</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-18T15:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594603#M1089302</link>
      <description>&lt;P&gt;can I see the config for both ACL and tunnel ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 15:50:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594603#M1089302</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-18T15:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594625#M1089304</link>
      <description>&lt;P&gt;Not sure if this is relevant but as I told you tunnel is up I can reach from A end device going to C end device, it's just the ASA - C is not pingable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site A - ASA confg:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list int1/1_cryptomap_2 extended permit ip object 10.16.169.0 object 10.16.174.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;crypto map int1/1_map 2 match address int1/1_cryptomap_2&lt;BR /&gt;crypto map int1/1_map 2 set peer B.B.B.B&lt;BR /&gt;crypto map int1/1_map 2 set ikev1 **********&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tunnel-group B.B.B.B type ipsec-l2l&lt;BR /&gt;tunnel-group B.B.B.B ipsec-attributes&lt;BR /&gt;ikev1 pre-shared-key *********&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;========================================================&lt;/P&gt;&lt;P&gt;access-list int1/1_cryptomap_3 extended permit ip object 10.16.169.0 object 10.16.174.128&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;crypto map int1/1_map 3 match address int1/1_cryptomap_3&lt;BR /&gt;crypto map int1/1_map 3 set peer C.C.C.C&lt;BR /&gt;crypto map int1/1_map 3 set ikev1 *****&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;tunnel-group C.C.C.C type ipsec-l2l&lt;BR /&gt;tunnel-group C.C.C.C ipsec-attributes&lt;BR /&gt;ikev1 pre-shared-key *************&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 16:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594625#M1089304</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-18T16:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594634#M1089305</link>
      <description>&lt;P&gt;NAT exception must include traffic for both.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;do you run packet tracer ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;packet-tracer input &lt;STRONG&gt;Inside&lt;/STRONG&gt;&amp;nbsp;icmp&amp;nbsp;ASA 8 0 Site-C detailed&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 16:35:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594634#M1089305</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-18T16:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594640#M1089306</link>
      <description>&lt;P&gt;As I said tunnel works fine the problem is Cisco ASA Site C is not replying from my ICMP request from Site A end device. Any other suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 16:35:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594640#M1089306</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-18T16:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping ASA from end device via IPSEC Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594680#M1089309</link>
      <description>&lt;P&gt;Do Packet-tracer ASA-A to Site-B&lt;BR /&gt;Do Packet-tracer ASA-A to Site C&lt;BR /&gt;check if the &lt;STRONG&gt;traffic-ID &amp;amp;&amp;nbsp;SPI&lt;/STRONG&gt; is same&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;check Other Site "Site-C" have route back to tunnel&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 17:23:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-from-end-device-via-ipsec-tunnel/m-p/4594680#M1089309</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-18T17:23:47Z</dc:date>
    </item>
  </channel>
</rss>

