<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FirePower/ASA | Can't Ping Interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684490#M13864</link>
    <description>&lt;P&gt;Yes, the "same-security-traffic" command was enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached is the output of packet tracer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.... ~zK s&lt;/P&gt;</description>
    <pubDate>Wed, 08 Aug 2018 21:08:00 GMT</pubDate>
    <dc:creator>zekebashi</dc:creator>
    <dc:date>2018-08-08T21:08:00Z</dc:date>
    <item>
      <title>FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684406#M13862</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am using an ASA on the Firepower 2110. I was trying to traffic flow between interfaces and configured one interface E1/5 with ip address 10.1.215.115/24; security-level 100 and another interface E1/6 with ip address 10.1.253.115/25; security-level 100). I allowed icmp from any to each interface. I created an ACL to allow icmp to each interface. I attahced two laptops to each interface( laptop215: 10.1.215.100/24- GW: 10.1.215.115 and laptop253: 10.1.253.100/24- GW: 10.1.253.115).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From laptop215, I can ping it's GW (10.1.215.115 just fine. From laptop253, I can also ping it's GW: 10.1.253.115 just fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the ASA, I can ping each interface just fine, but the issue I am facing is that when I try to ping from laptop215 to interface E1/6 - 10.1.253.115, it fails. The same thing happens when I try to ping from laptop253 to interface E1/5 - 10.1.215.115.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't figure out why I can't ping from each host (laptop) to the other interface or laptop. Why can't I ping from one host 10.1.253.100 to interface 10.1.251.115 or host 10.1.215.100 to 10.1.253.115?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any assistance would be greatly appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best, ~zK&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684406#M13862</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2020-02-21T16:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684417#M13863</link>
      <description>Hi, Do you have the command "same-security-traffic permit inter-interface" configured?&lt;BR /&gt;&lt;BR /&gt;If the 2 interfaces have the same security level, the default security policy will not permit traffic to pass between the two interfaces.&lt;BR /&gt;&lt;BR /&gt;If you do, can you please run packet-tracer and upload the output&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Wed, 08 Aug 2018 19:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684417#M13863</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-08T19:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684490#M13864</link>
      <description>&lt;P&gt;Yes, the "same-security-traffic" command was enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached is the output of packet tracer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.... ~zK s&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 21:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684490#M13864</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2018-08-08T21:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684507#M13920</link>
      <description>&lt;P&gt;Ok, packet-trace confirms it should be allowed.&lt;BR /&gt;&lt;BR /&gt;If I understand you correctly you are attempting to ping an interface of the ASA that you are not connected to (as in the interface connected to the other laptop). Try configuring the management-access command, reference &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/access_management.pdf" target="_self"&gt;here&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;If you cannot ping the laptops, do they have a local firewall enabled?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 21:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684507#M13920</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-08T21:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684513#M13922</link>
      <description>&lt;P&gt;That's correct. I am trying to ping from one laptop that's directly connected to one interface (10.1.251.x) to another on the ASA (10.1.253.x) and vice versa. Win FW is disabled on both laptops. The issue is when I try to ping from laptop 10.1.253.100 to ASA interface 10.1.251.115, ping fails!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I attached the ASA intfs configs and test results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks..&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 21:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684513#M13922</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2018-08-08T21:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684516#M13923</link>
      <description>&lt;P&gt;Ok, but did you enable the management-access command like I previously suggested?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 21:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684516#M13923</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-08T21:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684526#M13924</link>
      <description>&lt;P&gt;Yes. I did!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 06:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3684526#M13924</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2018-08-09T06:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3686164#M13925</link>
      <description>&lt;P&gt;I ended up rebooting the ASA and it worked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your assistance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 22:35:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3686164#M13925</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2018-08-10T22:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower/ASA | Can't Ping Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3686181#M13926</link>
      <description>&lt;P&gt;I have noticed a few areas lately when working with the Cisco ASA firewalls that a reboot or "clear conn" has fixed the odd issue(s). In the latest case I was running 9.9(2). Glad it worked out for you.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 23:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-can-t-ping-interfaces/m-p/3686181#M13926</guid>
      <dc:creator>Corey Davies</dc:creator>
      <dc:date>2018-08-10T23:34:17Z</dc:date>
    </item>
  </channel>
</rss>

