<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 - Virtual Private Network users cannot ping Local area network devices behind firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931642#M149666</link>
    <description>&lt;P&gt;Internet works fine from inside.&lt;BR /&gt;Ping is possible from inside to inside.&lt;BR /&gt;Ping is not possible inside to outside (8.8.8.8). &lt;BR /&gt;&lt;SPAN&gt;Local area network&lt;/SPAN&gt; devices have internet.&lt;BR /&gt;Virtual Private Network&amp;nbsp;users have internet, but cannot ping other Local area network devices except gateway (Firewall).&lt;/P&gt;
&lt;P&gt;I have two setups with same config, but different IP's and password.&lt;BR /&gt;Physical location different.&lt;BR /&gt;The remote one is running fine and the other have the issues for &lt;SPAN&gt;Virtual Private Network&lt;/SPAN&gt; users.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"&gt;Hello&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I hobe someone out there can help me to an solution of a rather annoying challenge.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Cisco A-S-A 5505 is something rather new to me, however I'm fairly good at setting up switches and other network hardware.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Mostly I'm use to&amp;nbsp;Hewlett&amp;nbsp;Packet switches.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;----- My post is ending up in the S-P,A'M filter. I will post the rest below -----&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:19:34 GMT</pubDate>
    <dc:creator>Mikke Wahlgreen</dc:creator>
    <dc:date>2019-03-12T08:19:34Z</dc:date>
    <item>
      <title>ASA 5505 - Virtual Private Network users cannot ping Local area network devices behind firewall</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931642#M149666</link>
      <description>&lt;P&gt;Internet works fine from inside.&lt;BR /&gt;Ping is possible from inside to inside.&lt;BR /&gt;Ping is not possible inside to outside (8.8.8.8). &lt;BR /&gt;&lt;SPAN&gt;Local area network&lt;/SPAN&gt; devices have internet.&lt;BR /&gt;Virtual Private Network&amp;nbsp;users have internet, but cannot ping other Local area network devices except gateway (Firewall).&lt;/P&gt;
&lt;P&gt;I have two setups with same config, but different IP's and password.&lt;BR /&gt;Physical location different.&lt;BR /&gt;The remote one is running fine and the other have the issues for &lt;SPAN&gt;Virtual Private Network&lt;/SPAN&gt; users.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"&gt;Hello&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I hobe someone out there can help me to an solution of a rather annoying challenge.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Cisco A-S-A 5505 is something rather new to me, however I'm fairly good at setting up switches and other network hardware.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Mostly I'm use to&amp;nbsp;Hewlett&amp;nbsp;Packet switches.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;----- My post is ending up in the S-P,A'M filter. I will post the rest below -----&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931642#M149666</guid>
      <dc:creator>Mikke Wahlgreen</dc:creator>
      <dc:date>2019-03-12T08:19:34Z</dc:date>
    </item>
    <item>
      <title>Seri-al communication using</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931643#M149667</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Seri-al communication using Put-ty and C-L-I, is something I have plenty of experience with&amp;nbsp;concerning&amp;nbsp;hardware.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have loads&amp;nbsp;of firewalls to test on and I'm trying to understand and change my former colleges setups.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My colleges and I use the firewall&amp;nbsp;on two different setups: An Internet Service Provider provided Static IP address and an Internet Service Provider provided dynamic IP address (DHCP) for the outside IP address.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Right now I'm trying to make my way through setting up our Static IP address setup on my own and I have encountered a challenge. Even my colleges have not been able to solve it when going through the config.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have been googling my issue and found plenty of other similar topics here in this forum, however none of them have led me to a solution.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As described in the summary I have two ASA 5505, one at the office for testing and one in the field.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The one in the field is working as a charm and has Setup 2 (sanitized version).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have access to it through VPN and then ASDM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The other for testing is located here at my office. It is not working as intended and has Setup 1&amp;nbsp;(sanitized version), which seems to be a replica of Setup 2 with only change in the VPN-key and the outside IP address.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have access to connect to it with: Serial for programming, VPN, local Ethernet/Patch cable, and ASDM&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm using Cisco VPN client on Win7 for VPN connection. I'm also familiar with the Cisco AnyConnect Secure Mobility Client and running it on&amp;nbsp;Win10 as a beginner.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Off topic: To help others with RS232 problems: My USB-serial converter/adapter is bugging me (Prolific driver) and I'm using Terminal by Bray combined with Putty for RS232 communication without having to restart every time Putty crashed the converter/adapter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;The ASA 5505 at the remote location have a DSL Modem with a Static IP address provided from the ISP. (x.y.z.t subnet 255.255.255.252)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Whereas the ASA 5505 I have in the office have a Static IP address on our local Office network. (10.10.10.230 subnet 255.255.255.0)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I can login on the Office ASA&amp;nbsp;with VPN, from an IP address :10.10.10.50 subnet 255.255.255.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Here I can ping the GW, but not other LAN devices such as 192.168.10.2, 192.168.10.4, or 192.168.10.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;From several&amp;nbsp;of the LAN devices (198.168.10.10 and 198.168.10.235) I cannot ping 8.8.8.8, but I can ping the&amp;nbsp;GW,&amp;nbsp;192.168.10.2,&amp;nbsp;and&amp;nbsp;192.168.10.4.&lt;BR /&gt;All LAN devices are online.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the remote ASA I can login with VPN and ping GW,&amp;nbsp;192.168.10.2, 192.168.10.4, or 192.168.10.10 easily.&lt;BR /&gt;All LAN devices are online and can ping 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What seems odd is that the two configs are very similar except for external IPs and passwords.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have tried to move my Office ASA to a mobile boardband router with a statik IP of 192.168.1.254 subnet 255.255.255.0 and a gateway of 192.168.1.1. The DHCP range of this router is between 50-99. Here I see the same behavior when I'm connected with a laptop and have DHCP leased IP of 192.168.1.55 subnet 255.255.255.0. I can connect on the VPN, however not cable of pinging anything except the GW.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the Office ASA my IP address when connected via VPN is 192.168.11.1 and on the remote&amp;nbsp;ASA my IP address when connected via VPN is 192.168.11.2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What am I doing wrong on my test setup for that not to work?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would like to keep my current images on the ASA (asa901-k8.bin&amp;nbsp;and&amp;nbsp;asdm-711-52.bin), even if there have been updates, due to policies from my colleges.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anything you dream on I have forgotten to mention please don't&amp;nbsp;hesitate&amp;nbsp;to ask.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 12:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931643#M149667</guid>
      <dc:creator>Mikke Wahlgreen</dc:creator>
      <dc:date>2016-09-26T12:56:40Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931644#M149668</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Since we are able to ping the inside IP of the ASA from the VPN users that means pings are reaching to the ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you apply debug &lt;G class="gr_ gr_132 gr-alert gr_spell gr_disable_anim_appear ContextualSpelling ins-del multiReplace" id="132" data-gr-id="132"&gt;icmp&lt;/G&gt; trace on the ASA and initiate a ping from the VPN client towards any device behind the ASA and check if the pings reach to the ASA ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you see requests hitting the ASA and no replies then probably we are missing a reverse route on the downstream switch for the&amp;nbsp;VPN-pool 192.168.10.1-192.168.10.49.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Try configuring a static route for the pool on the switch with ASA as its next hop.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Use &lt;G class="gr_ gr_495 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="495" data-gr-id="495"&gt;undebug&lt;/G&gt; all to stop the debugs.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 13:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931644#M149668</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-09-26T13:28:52Z</dc:date>
    </item>
    <item>
      <title>When pinging the GW on a VPN,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931645#M149669</link>
      <description>&lt;P&gt;When pinging the GW on a VPN, the ASA gives the following:&lt;BR /&gt;ICMP echo request from 192.168.10.1 to 192.168.1.1 ID=1 seq=7 len=32&lt;BR /&gt;ICMP echo reply from 192.168.1.1 to 192.168.10.1 ID=1 seq=7 len=32&lt;/P&gt;
&lt;P&gt;When pinging a LAN device on a VPN, the ASA gives the following:&lt;BR /&gt;ICMP echo request from outside:192.168.10.1 to inside:192.168.1.2 ID=1 seq=13 len=32&lt;BR /&gt;NO REPLY&lt;/P&gt;
&lt;P&gt;I'll try to create the static route you are describing, however my knowledge on how to is rather limited on the ASA.&lt;/P&gt;
&lt;P&gt;As I see it you want me to configure a static route from 192.168.10.1 to 192.168.1.1 is that correct understood?&lt;/P&gt;
&lt;P&gt;Should my static route for 0.0.0.0 subnet 0.0.0.0 pointing at 10.10.10.254 not take care of that?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 07:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931645#M149669</guid>
      <dc:creator>Mikke Wahlgreen</dc:creator>
      <dc:date>2016-09-27T07:04:01Z</dc:date>
    </item>
    <item>
      <title>OK I'm properly doing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931646#M149670</link>
      <description>&lt;P&gt;OK I'm properly doing something I should not, I get the following errors trying to set up yet another static route in the ASDM:&lt;/P&gt;
&lt;P&gt;[ERROR] route inside 192.168.10.0 255.255.255.192 192.168.1.1 1&lt;BR /&gt; %Invalid next hop address, it belongs to one of our interfaces&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[ERROR] route &lt;/SPAN&gt;&lt;SPAN&gt;out&lt;/SPAN&gt;&lt;SPAN&gt;side 192.168.10.0 255.255.255.192 192.168.1.1 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;%Invalid next hop address, it belongs to one of our interfaces&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Could someone please explain me the following:&lt;BR /&gt;What to set Interface on: inside or outside?&lt;BR /&gt;What to set Network for: NETWORK_OBJ_192.168.170.0_26,&amp;nbsp;NETWORK_Vpn (similar) or something different?&lt;BR /&gt;What to set as my Gateway: 10.10.10.254?&lt;/P&gt;
&lt;P&gt;To create the reverse route Aditay is talking about.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 07:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-virtual-private-network-users-cannot-ping-local-area/m-p/2931646#M149670</guid>
      <dc:creator>Mikke Wahlgreen</dc:creator>
      <dc:date>2016-09-27T07:04:02Z</dc:date>
    </item>
  </channel>
</rss>

