<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot ping to server outside ASA despite permitting icmp traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598067#M1089438</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1345409"&gt;@mav773&lt;/a&gt; that host is 192.168.4.1 right? .....your nat rule only applies to that ip&lt;/P&gt;
&lt;P&gt;Can you ping&amp;nbsp; 8.8.8.8 directly from the ASA itself?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Apr 2022 18:33:03 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-04-22T18:33:03Z</dc:date>
    <item>
      <title>Cannot ping to server outside ASA 5506 despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598035#M1089427</link>
      <description>&lt;P&gt;I have a packet tracer project I am working on and I want to have it use a 5506 firewall. However, I cannot ping the 8.8.8.8 server on the outside of the firewall. I can ping the IP on the inside of the ASA, but no IP's on the outside can be pinged. The network has three routers. 2 are the active and standby routers using HSRP, and the 3rd router is the edge router that connects the 2 HSRP routers to the firewall. The ASA firewall is connected to an external router that is connected to a server. I cannot ping from a pc inside the network to the server or router on the outside of the ASA firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my running config for my ASA. Any ideas why this isn't working?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/1&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.4.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/2&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 10.1.1.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network INSIDE-NET&lt;/P&gt;&lt;P&gt;host 192.168.4.1&lt;/P&gt;&lt;P&gt;nat (inside,outside) static 110.1.1.52&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route inside 192.168.4.0 255.255.255.0 192.168.4.1 1&lt;/P&gt;&lt;P&gt;route inside 192.168.0.0 255.255.0.0 192.168.4.1 1&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 10.1.1.4 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list AL extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list AL extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list AL extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list AL extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-group AL in interface outside&lt;/P&gt;&lt;P&gt;access-group AL in interface inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect icmp&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 17:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598035#M1089427</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T17:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598038#M1089428</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1345409"&gt;@mav773&lt;/a&gt; are you sure your NAT address &lt;STRONG&gt;(1&lt;/STRONG&gt;10.1.1.52) is correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run packet-tracer from the CLI and provide the output "packet-tracer input inside icmp 192.168.4.1 8 0 8.8.8.8".&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 17:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598038#M1089428</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-22T17:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598046#M1089430</link>
      <description>&lt;P&gt;Hi Rob, thank you for your reply. I'm having trouble running that command. I pasted it in the ASA CLI but I keep getting "Invalid input detected at '^' marker." pointing to the word "packet" in the command. I can't find any solutions online, what am I doing wrong?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 17:55:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598046#M1089430</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T17:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598048#M1089432</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1345409"&gt;@mav773&lt;/a&gt; please provide a screenshot of what you pasted and the error.&lt;/P&gt;
&lt;P&gt;Is that NAT address correct or not?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 17:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598048#M1089432</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-22T17:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598052#M1089433</link>
      <description>&lt;P&gt;Here is the screenshot. I changed the NAT address recently from 192.168.4.2 to the current one. Is the NAT address supposed to match something? I thought it didn't matter what the NAT address was because it's translated from the host IP, so I don't know if it is correct or not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598052#M1089433</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T18:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598055#M1089434</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1345409"&gt;@mav773&lt;/a&gt; well 110.1.1.52 would need to be routed to the outside interface of the ASA, otherwise upstream devices won't know how to route the return packet. Use 10.1.1.52 which is in the same network as the ASA's outside interface or NAT behind the ASA's outside interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looks like you are using packet tracer application?....perhaps packet-tracer does not work using this application.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598055#M1089434</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-22T18:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598060#M1089435</link>
      <description>&lt;P&gt;Okay, I changed the IP to 10.1.1.52, thanks for explaining that. Yes, I am using the Cisco Packet Tracer application.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598060#M1089435</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T18:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598064#M1089436</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1345409"&gt;@mav773&lt;/a&gt; did that resolve the issue?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598064#M1089436</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-22T18:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598066#M1089437</link>
      <description>&lt;P&gt;No, same issue. When I try to ping the outside network from a PC inside the network, it still says destination host unreachable.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598066#M1089437</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T18:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598067#M1089438</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1345409"&gt;@mav773&lt;/a&gt; that host is 192.168.4.1 right? .....your nat rule only applies to that ip&lt;/P&gt;
&lt;P&gt;Can you ping&amp;nbsp; 8.8.8.8 directly from the ASA itself?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598067#M1089438</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-22T18:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598068#M1089439</link>
      <description>&lt;P&gt;The PC I am pinging from is 192.168.1.100. The router is the one with the 192.168.4.1 address. I will attach a screenshot of the network diagram.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ASA can ping 8.8.8.8 and has a 100% success rate.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:40:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598068#M1089439</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T18:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598073#M1089440</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1345409"&gt;@mav773&lt;/a&gt; well that would not be natted, only traffic from the host 192.168.4.1 would be translated.&lt;/P&gt;
&lt;P&gt;Unless you are not expecting to translate the trafffic?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a NAT rule cover all your internal networks, example:-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;object network INSIDE-NET&lt;BR /&gt;&amp;nbsp;subnet 192.168.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:48:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598073#M1089440</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-22T18:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598075#M1089441</link>
      <description>&lt;P&gt;That makes sense, I changed the NAT rule to that one. Unfortunately, I am still getting the same issue when pinging from a PC to the outside server.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 18:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598075#M1089441</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T18:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA 5506 despite permitting icmp tra</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598088#M1089442</link>
      <description>&lt;P&gt;Need to conifg static route in external router for retrun traffic from 8.8.8.8 to PC.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 19:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598088#M1089442</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-22T19:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA 5506 despite permitting icmp tra</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598094#M1089443</link>
      <description>&lt;P&gt;I have the static route of 0.0.0.0 going to the next hop of the ASA outside IP interface. I added another static route for the 8.8.8.0 network to go to the ASA outside interface as well. Still no change.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 20:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598094#M1089443</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T20:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598104#M1089444</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to rule out a NAT issue, on the 1941 router can you add this route as a test -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ip route 192.168.0.0 255.255.0.0 10.1.1.2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and then try pinging.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 20:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598104#M1089444</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2022-04-22T20:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598112#M1089445</link>
      <description>&lt;P&gt;Hi Jon, thank you for your reply. I ran that command and I am still getting the same "Destination host unreachable" response after pinging.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 20:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598112#M1089445</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T20:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598115#M1089446</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do your internal routers have routes or default routes pointing to the firewall ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like the traffic is not being sent to the firewall so can you do a traceroute from the PC to the server and post the results.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 20:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598115#M1089446</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2022-04-22T20:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA despite permitting icmp traffic</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598116#M1089447</link>
      <description>&lt;P&gt;The internal routers do have a RIP routing table. I am also able to ping the inside interface of the firewall. I did a traceroute to the server first, and then I did a traceroute to the inside interface of the firewall. Here is the screenshot.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 21:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598116#M1089447</guid>
      <dc:creator>mav773</dc:creator>
      <dc:date>2022-04-22T21:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping to server outside ASA 5506 despite permitting icmp tra</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598117#M1089448</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have the static route of 0.0.0.0 going to the next hop of the ASA outside IP interface &lt;FONT color="#FF0000"&gt;&amp;lt;- this config in external router ??&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;NO&lt;/FONT&gt; object network INSIDE-NET &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;&amp;lt;- you must delete this NAT otherwise this still effect your traffic even after add new NAT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;host 192.168.4.1&lt;/P&gt;&lt;P&gt;nat (inside,outside) static 110.1.1.52&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network INSIDE-NET&lt;/P&gt;&lt;P&gt;Subnet &amp;nbsp;192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic interface&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 21:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-to-server-outside-asa-5506-despite-permitting-icmp/m-p/4598117#M1089448</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-22T21:01:27Z</dc:date>
    </item>
  </channel>
</rss>

