<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to ping a subinterface on FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253927#M1119153</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;The connection looks like below, what I try to do is try to ping from the internal network to the sub-interface on the FTD. I can ping all the hosts in the same subnet behind that sub-interface, but just can not ping the sub-interface ip address.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cxu21_0-1738098716122.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238655i917CC77CFDFD4E14/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cxu21_0-1738098716122.png" alt="cxu21_0-1738098716122.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2025 21:14:53 GMT</pubDate>
    <dc:creator>cxu21</dc:creator>
    <dc:date>2025-01-28T21:14:53Z</dc:date>
    <item>
      <title>How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253445#M1119128</link>
      <description>&lt;P&gt;We have a 1140 FTD managed by FMC, on the FTD, there is a paricular subinterface that required to be pingable.&lt;/P&gt;
&lt;P&gt;We had the rule configured as below but none of the interface is pingable.&lt;/P&gt;
&lt;P&gt;Is there anything we missed?&lt;/P&gt;
&lt;P&gt;We do not need to ping all subinterface, only 1 is required to be able to ping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cxu21_0-1738020796369.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238626i8DE07A096426733E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cxu21_0-1738020796369.png" alt="cxu21_0-1738020796369.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 23:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253445#M1119128</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-27T23:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253484#M1119130</link>
      <description>&lt;P&gt;From FMC &amp;gt;platform setting &amp;gt;icmp&lt;/P&gt;
&lt;P&gt;Allow icmp in interface and specify subnet can ping to this interface&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 03:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253484#M1119130</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-28T03:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253492#M1119131</link>
      <description>&lt;P&gt;Thank you for your prompt response.&lt;/P&gt;
&lt;P&gt;I assume this is the place you refer to, we already allowed icmp between different zones, but still could not ping.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cxu21_0-1738035727033.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238629iDE05CB309AB6B8BF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cxu21_0-1738035727033.png" alt="cxu21_0-1738035727033.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 03:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253492#M1119131</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-28T03:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253583#M1119133</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1297635"&gt;@cxu21&lt;/a&gt; the FTD responds to ICMP traffic sent to the interface that traffic comes in on. In other words, if you are connected behind Eth1 you can ping Eth1, but you would not be able to ping through the FTD to ping another of the FTD's interface. That is by design. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 08:53:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253583#M1119133</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-28T08:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253712#M1119138</link>
      <description>&lt;P&gt;can I see how you config platform setting ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 13:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253712#M1119138</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-28T13:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253747#M1119144</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;made a very good point. If you are trying to ping or reach an interface of the firewall coming from another that will not be allowed by design and no security rule will work around it. This behaviour was the same on Cisco ASA and it is still the same on the FTDs.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 13:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253747#M1119144</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-28T13:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253927#M1119153</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;The connection looks like below, what I try to do is try to ping from the internal network to the sub-interface on the FTD. I can ping all the hosts in the same subnet behind that sub-interface, but just can not ping the sub-interface ip address.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cxu21_0-1738098716122.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238655i917CC77CFDFD4E14/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cxu21_0-1738098716122.png" alt="cxu21_0-1738098716122.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253927#M1119153</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-28T21:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253934#M1119155</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1297635"&gt;@cxu21&lt;/a&gt; so you are trying to ping the FTD sub-interface the internal network is connected to? that should work, perhaps routing issues either on the switch or FTD - check the routing tables. Can the FTD ping the internal network? Take a packet capture and confirm the ping is received by the FTD. Can the internal network ping through the FTD to something on the other side of the FTD?&lt;/P&gt;
&lt;P&gt;If you aren't ping the sub-interace that leads to the internal network then it won't work.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253934#M1119155</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-28T21:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253944#M1119156</link>
      <description>&lt;P&gt;I don't see how you config the icmp in platform.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also are you using trunk between SW and ftd?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253944#M1119156</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-28T21:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253952#M1119158</link>
      <description>&lt;P&gt;Yes, the connection between switch and FTD is configured as trunk using port channel for HA purpose. Here is the demo of the configuration.&lt;/P&gt;
&lt;P&gt;interface Port-channel11&lt;BR /&gt;description To Primary&lt;BR /&gt;switchport trunk native vlan 99&lt;BR /&gt;switchport trunk allowed vlan 3,4,5,6&lt;BR /&gt;switchport mode trunk&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/0/24&lt;BR /&gt;switchport trunk native vlan 99&lt;BR /&gt;switchport trunk allowed vlan 3,4,5,6&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;auto qos trust dscp&lt;BR /&gt;channel-group 11 mode active&lt;/P&gt;
&lt;P&gt;Here is the icmp configuration screenshot in platform settings&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="icmp.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238660iB999A74DC3C4D4C6/image-size/large?v=v2&amp;amp;px=999" role="button" title="icmp.png" alt="icmp.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253952#M1119158</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-28T22:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253955#M1119159</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;I can ping between any hosts behind different subinterface on the FTD from internal network and can ping the internal network from FTD, just can not ping from internal network to the subinterface ip address.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253955#M1119159</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-28T22:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253959#M1119160</link>
      <description>&lt;P&gt;Thanks for sharing more detail&lt;/P&gt;
&lt;P&gt;In zone/interface do you see subinterface name or interface name connect to internal? If yes select it.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253959#M1119160</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-28T22:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253965#M1119161</link>
      <description>&lt;P&gt;I do not see subinterface name in the zone/interface field. I just wonder if I need to configure ARP for that particular subinterface?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cxu21_0-1738103406244.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238662i50680B0BA6FAB80E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cxu21_0-1738103406244.png" alt="cxu21_0-1738103406244.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253965#M1119161</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-28T22:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253969#M1119162</link>
      <description>&lt;P&gt;No need,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can İ see from device mgmt &amp;gt;interface&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:40:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253969#M1119162</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-28T22:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253977#M1119163</link>
      <description>&lt;P&gt;Here is the subinterface configuration. under IPv4, it selects using static with ip address and under Advanced, enable the anti spoofing, the other are default.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cxu21_0-1738104443997.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238663i78A1C410046C1B7D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cxu21_0-1738104443997.png" alt="cxu21_0-1738104443997.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cxu21_1-1738104570577.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238664i65D7FDF9D24FC408/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cxu21_1-1738104570577.png" alt="cxu21_1-1738104570577.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253977#M1119163</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-28T22:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253981#M1119164</link>
      <description>&lt;P&gt;Vlan Id 1 &amp;lt;&amp;lt;- not allow in trunk?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:54:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253981#M1119164</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-28T22:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253985#M1119165</link>
      <description>&lt;P&gt;It is allowed in the trunk&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 23:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253985#M1119165</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-28T23:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253986#M1119166</link>
      <description>&lt;P&gt;Your share config say opposite&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Port-channel11&lt;BR /&gt;description To Primary&lt;BR /&gt;switchport trunk native vlan 99&lt;BR /&gt;switchport trunk allowed vlan 3,4,5,6&lt;BR /&gt;switchport mode trunk&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/0/24&lt;BR /&gt;switchport trunk native vlan 99&lt;BR /&gt;switchport trunk allowed vlan 3,4,5,6&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;auto qos trust dscp&lt;BR /&gt;channel-group 11 mode active&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 23:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253986#M1119166</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-28T23:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253987#M1119167</link>
      <description>&lt;P&gt;sorry, that is just a demo, the real configuration allowed vlan 1&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 23:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5253987#M1119167</guid>
      <dc:creator>cxu21</dc:creator>
      <dc:date>2025-01-28T23:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to ping a subinterface on FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5254123#M1119172</link>
      <description>&lt;P&gt;So SW use vlan 99 or vlan 1 as native ?&lt;/P&gt;
&lt;P&gt;If it use vlan1 use any unuse other vlan as native in trunk between SW and FPR.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 10:01:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-ping-a-subinterface-on-ftd/m-p/5254123#M1119172</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-29T10:01:55Z</dc:date>
    </item>
  </channel>
</rss>

