<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not able to ping a sepcific network from inside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782684#M160052</link>
    <description>&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;I am not able to ping a specific subnet via the inside interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62.211.xxx.xxx/27 &amp;nbsp;&amp;nbsp; ----&amp;gt; WAN1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62.211.xxx.xxx/27 -----&amp;gt; DMZ1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.250.250.254/24 -----&amp;gt; Inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.10.254/24 -----&amp;gt; Remote-Office-1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.151.2.6/24 ------&amp;gt; Remote-Office-2 --------------------------&amp;gt; 172.16.25.0/24&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;Behind the Remote Office 2,&amp;nbsp; I have another network 172.16.25.0/24&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;I am not able to ping 172.16.25.0/24 network from any interface except&amp;nbsp; GigabitEthernet0/4&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001# ping Remote-Office-2 172.16.25.11 repeat 100&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Sending 5, 100-byte ICMP Echos to 172.16.25.11, timeout is 2 seconds:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Success rate is 100 percent (100/100), round-trip min/avg/max = 1/1/1 ms&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001# ping Remote-Office-1 172.16.25.11&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Sending 5, 100-byte ICMP Echos to 172.16.25.11, timeout is 2 seconds:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;?????&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Success rate is 0 percent (0/5)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001# sh route | i 172.16.25.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.25.0 255.255.255.0 [1/0] via 10.151.2.5, Remote-Office-2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please help&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Abdul&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:14:12 GMT</pubDate>
    <dc:creator>ftitsecurity</dc:creator>
    <dc:date>2019-03-12T07:14:12Z</dc:date>
    <item>
      <title>Not able to ping a sepcific network from inside interface</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782684#M160052</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;I am not able to ping a specific subnet via the inside interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62.211.xxx.xxx/27 &amp;nbsp;&amp;nbsp; ----&amp;gt; WAN1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62.211.xxx.xxx/27 -----&amp;gt; DMZ1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.250.250.254/24 -----&amp;gt; Inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.10.254/24 -----&amp;gt; Remote-Office-1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;GigabitEthernet0/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.151.2.6/24 ------&amp;gt; Remote-Office-2 --------------------------&amp;gt; 172.16.25.0/24&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;Behind the Remote Office 2,&amp;nbsp; I have another network 172.16.25.0/24&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 12pt;"&gt;I am not able to ping 172.16.25.0/24 network from any interface except&amp;nbsp; GigabitEthernet0/4&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001# ping Remote-Office-2 172.16.25.11 repeat 100&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Sending 5, 100-byte ICMP Echos to 172.16.25.11, timeout is 2 seconds:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Success rate is 100 percent (100/100), round-trip min/avg/max = 1/1/1 ms&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001# ping Remote-Office-1 172.16.25.11&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Sending 5, 100-byte ICMP Echos to 172.16.25.11, timeout is 2 seconds:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;?????&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Success rate is 0 percent (0/5)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001# sh route | i 172.16.25.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.25.0 255.255.255.0 [1/0] via 10.151.2.5, Remote-Office-2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;ASA001#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please help&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Abdul&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782684#M160052</guid>
      <dc:creator>ftitsecurity</dc:creator>
      <dc:date>2019-03-12T07:14:12Z</dc:date>
    </item>
    <item>
      <title>Abdul</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782685#M160053</link>
      <description>&lt;P&gt;Abdul&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You have not provided information about how the remote offices are connected and that might shed some light on the situation. But the issue seems pretty clear. You have configured the ASA with information that says that 172.16.25.0 is reached via Remote-Office-2. So why would you attempt to reach an address in that subnet by going through Remote-Office-1? If your ping packet did reach Remote-Office-1 how would it forward that packet to Remote-Office-2?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 16:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782685#M160053</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2016-02-03T16:07:29Z</dc:date>
    </item>
    <item>
      <title>Because Remote-Office-1 needs</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782686#M160054</link>
      <description>&lt;P&gt;Because Remote-Office-1 needs to connect a server 172.16.25.11 which is behind remote-office-2&lt;/P&gt;
&lt;P&gt;Remote-Office-1 Security Level is 100&lt;/P&gt;
&lt;P&gt;Remote-Office-2 Security Level is 100&lt;/P&gt;
&lt;P&gt;Inside Security level is 100&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And i have also checked the option that "Enable traffic between two or more interfaces with same security level"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Abdul&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 16:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782686#M160054</guid>
      <dc:creator>ftitsecurity</dc:creator>
      <dc:date>2016-02-03T16:39:30Z</dc:date>
    </item>
    <item>
      <title>Abdul</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782687#M160055</link>
      <description>&lt;P&gt;Abdul&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for the&amp;nbsp;explanation. Checking the option for Enable traffic between interfaces is an essential first step in enabling Office 1 to access the server which is at Office 2. There are possibly other steps that might be needed, but without knowing more about your environment it is not possible to know exactly what is needed. Some of the possible issues include: specify the network in VPN configurations, address translations/NAT exemptions for the traffic, access policies on the interfaces, routing logic at the remote sites.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And none of that relates to the issue in your first post about pinging the server address by going to Office 1. If the server is at Office 2 then why would you want to send a ping packet for the server to Office 1?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rick&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 16:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-ping-a-sepcific-network-from-inside-interface/m-p/2782687#M160055</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2016-02-03T16:51:10Z</dc:date>
    </item>
  </channel>
</rss>

