<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is your network on the other in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067985#M146546</link>
    <description>&lt;P&gt;Is your network on the other end, also an Internal Network and have same or higher security level as management?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Rikshit&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2017 12:04:53 GMT</pubDate>
    <dc:creator>rikshit4aggarwal</dc:creator>
    <dc:date>2017-02-13T12:04:53Z</dc:date>
    <item>
      <title>Can't ping inside interface coming from a network across MPLS</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067984#M146545</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I've been facing this issue. I can't ping the ASA interface from a network across the MPLS connection. I can ping from local LAN.&lt;BR /&gt;I have a Cisco ASA 5510.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.4(7)30&lt;BR /&gt;Device Manager Version 7.1(4)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Some of my configuration&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt; inspect icmp&lt;BR /&gt; inspect icmp error&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;management-access Inside&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It's not route, because access to the internal LAN across the MPLS works fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Watching the logs on ASDM and it's being allowed.&lt;BR /&gt;&lt;BR /&gt;I run out of options.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:55:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067984#M146545</guid>
      <dc:creator>wribeiro2305</dc:creator>
      <dc:date>2019-03-12T08:55:33Z</dc:date>
    </item>
    <item>
      <title>Is your network on the other</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067985#M146546</link>
      <description>&lt;P&gt;Is your network on the other end, also an Internal Network and have same or higher security level as management?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Rikshit&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 12:04:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067985#M146546</guid>
      <dc:creator>rikshit4aggarwal</dc:creator>
      <dc:date>2017-02-13T12:04:53Z</dc:date>
    </item>
    <item>
      <title>You cannot ping (or ssh/https</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067986#M146550</link>
      <description>&lt;P&gt;You cannot ping (or ssh/https for that matter) to an interface of an ASA when coming in through another interface. This is by design and cannot be changed AFAIK. The only exception to this is when you are coming in through a VPN tunnel interface on another interface - for which "management-access" is required.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 12:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067986#M146550</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-02-13T12:09:21Z</dc:date>
    </item>
    <item>
      <title>We have monitoring Server</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067987#M146553</link>
      <description>&lt;P&gt;We have monitoring Server within 192.168.22.0/24 on HQ. However I can't ping my Inside interface on a ASA (192.168.100.0/24) in a remote site across our MPLS link. I can ping the MPLS interface and I can ping Servers within 192.168.100.0/24, but not the ASA interface.&lt;BR /&gt;&lt;BR /&gt;Inside interface on the ASA 192.168.100.201 has the same security level as management (100).&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 12:14:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067987#M146553</guid>
      <dc:creator>wribeiro2305</dc:creator>
      <dc:date>2017-02-13T12:14:47Z</dc:date>
    </item>
    <item>
      <title> Hi Rahul,  I can't do either</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067988#M146556</link>
      <description>&lt;P&gt;&amp;nbsp;Hi Rahul,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;I can't do either of them (ping, ssh or https).&lt;BR /&gt;&amp;nbsp;I have the management-access enabled on Inside interface.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;The ACL is allowing and when I watch the logs on ASDM I can see the connection building up.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 12:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067988#M146556</guid>
      <dc:creator>wribeiro2305</dc:creator>
      <dc:date>2017-02-13T12:21:57Z</dc:date>
    </item>
    <item>
      <title>Yes, that is by design. If</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067989#M146558</link>
      <description>&lt;P&gt;Yes, that is by design. If you are coming in via an MPLS interface, you wont be able to access the ASA inside interface. You can access everything else on the inside network, except the inside interface. It does not matter what ACL rules are in place. You can only ping the inside interface from the inside network, Mpls interface from MPLS network etc.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 12:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067989#M146558</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-02-13T12:32:01Z</dc:date>
    </item>
    <item>
      <title>Thanks for the info... I didn</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067990#M146560</link>
      <description>&lt;P&gt;Thanks for the info... I didn't know that.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 12:37:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067990#M146560</guid>
      <dc:creator>wribeiro2305</dc:creator>
      <dc:date>2017-02-13T12:37:48Z</dc:date>
    </item>
    <item>
      <title>Yeah this feature is a carry</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067991#M146562</link>
      <description>&lt;P&gt;Yeah this feature is a carry over from the PIX days. It has been documented here:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;The ASA only responds to ICMP traffic sent to the interface that traffic comes in on; you cannot send ICMP traffic through an interface to a far interface.&lt;/PRE&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/admin_management.html&lt;/P&gt;
&lt;P&gt;Also doc bug is here:&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCtd86651/?referring_site=bugquickviewclick&lt;/P&gt;
&lt;P&gt;Since it mentions only ping, SSH and HTTPS may be still possible if you add the right access rules. I have not tested this so not sure of the behavior.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 12:49:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067991#M146562</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-02-13T12:49:01Z</dc:date>
    </item>
    <item>
      <title>If you have an MPLS interface</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067992#M146564</link>
      <description>&lt;P&gt;If you have an MPLS interface configured on ASA, then you cannot ping internal interface..What security level have you configured on the MPLS interface.??You can only ping the MPLS interface and then the traffic will be redirected through the Internal interface to the internal resources depending on the config. done in ASA&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Rikshit&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 12:53:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-inside-interface-coming-from-a-network-across-mpls/m-p/3067992#M146564</guid>
      <dc:creator>rikshit4aggarwal</dc:creator>
      <dc:date>2017-02-13T12:53:42Z</dc:date>
    </item>
  </channel>
</rss>

