<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do you see any drops in the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864898#M167366</link>
    <description>&lt;P&gt;Do you see any drops in the ASDM real time log viewer when you ping the outside IP?&lt;/P&gt;
&lt;P&gt;Just for testing could you add permit icmp any any on the outside interface ACL?&lt;/P&gt;
&lt;P&gt;What version ASA are you running?&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2016 21:52:04 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2016-03-16T21:52:04Z</dc:date>
    <item>
      <title>Unable to ping ASA outside interface</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864897#M167365</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I am not able to ping the outside interface IP from internet. But I can ping from the ASA to internet.&lt;/P&gt;
&lt;P&gt;FW# ping 4.2.2.2 re 1&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 1, 100-byte ICMP Echos to 4.2.2.2, timeout is 2 seconds:&lt;BR /&gt;!&lt;BR /&gt;Success rate is 100 percent (1/1), round-trip min/avg/max = 70/70/70 ms&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;FW# sh run icmp &lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any outside&lt;/P&gt;
&lt;P&gt;FW#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please &amp;nbsp;help?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;CF&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864897#M167365</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2019-03-12T07:30:08Z</dc:date>
    </item>
    <item>
      <title>Do you see any drops in the</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864898#M167366</link>
      <description>&lt;P&gt;Do you see any drops in the ASDM real time log viewer when you ping the outside IP?&lt;/P&gt;
&lt;P&gt;Just for testing could you add permit icmp any any on the outside interface ACL?&lt;/P&gt;
&lt;P&gt;What version ASA are you running?&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 21:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864898#M167366</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2016-03-16T21:52:04Z</dc:date>
    </item>
    <item>
      <title>I tried permitting ICMP in</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864899#M167367</link>
      <description>&lt;P&gt;I tried permitting ICMP in the outside ACL. But still no luck.&lt;/P&gt;
&lt;P&gt;I am running&amp;nbsp;asa9.1(7).&lt;/P&gt;
&lt;P&gt;CF&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 16:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864899#M167367</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2016-03-18T16:00:41Z</dc:date>
    </item>
    <item>
      <title>Do a "debug icmp trace" on</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864900#M167368</link>
      <description>&lt;P&gt;Do a "debug &lt;G class="gr_ gr_19 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="19" data-gr-id="19"&gt;icmp&lt;/G&gt; trace" on the ASA while pinging to see if you get the pings from the host on &lt;G class="gr_ gr_106 gr-alert gr_gramm undefined Grammar only-ins replaceWithoutSep" id="106" data-gr-id="106"&gt;internet&lt;/G&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I hope you don't have a static nat translating everything to an internal resource.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 16:16:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864900#M167368</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-03-18T16:16:37Z</dc:date>
    </item>
    <item>
      <title>Hi Dinesh,</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864901#M167369</link>
      <description>&lt;P&gt;Hi Dinesh,&lt;/P&gt;
&lt;P&gt;I can't do a debug on the device since its production ASA. However, I created packet capture on the ASA. But it doesn't show any hits.&lt;/P&gt;
&lt;P&gt;fw-01# sh access-list Test&lt;BR /&gt;access-list Test; 2 elements; name hash: 0x173428b0&lt;BR /&gt;access-list Test line 1 extended permit icmp host x.x.x.x&amp;nbsp;any4 (hitcnt=0) 0x0b3d0029 &lt;BR /&gt;access-list Test line 2 extended permit icmp any4 host x.x.x.x&amp;nbsp;(hitcnt=0) 0x5c57c3b6&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;fw-01# sh capture &lt;BR /&gt;capture Test type raw-data access-list Test buffer 2000 interface outside headers-only &lt;STRONG&gt;[Capturing - 0 bytes]&lt;/STRONG&gt; &lt;BR /&gt;fw-01#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, I have ran packet-tracer for ICMP type 8 code 0 from 4.2.2.2 to outside public IP:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;It shows that the packet will be allowed.&lt;/P&gt;
&lt;P&gt;There is not static NAT&amp;nbsp;to translate everything into internal.&lt;/P&gt;
&lt;P&gt;CF&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 16:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864901#M167369</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2016-03-18T16:44:12Z</dc:date>
    </item>
    <item>
      <title>Is this ASA internet facing</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864902#M167370</link>
      <description>&lt;P&gt;Is this ASA internet facing device ?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 17:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864902#M167370</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-03-18T17:39:49Z</dc:date>
    </item>
    <item>
      <title>Yes, it is.</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864903#M167371</link>
      <description>&lt;P&gt;Yes, it is.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 19:19:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864903#M167371</guid>
      <dc:creator>Cisco Freak</dc:creator>
      <dc:date>2016-03-18T19:19:58Z</dc:date>
    </item>
    <item>
      <title>Check if there are no drops</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864904#M167372</link>
      <description>&lt;P&gt;Check if&amp;nbsp;there are no drops on ASA (run "cap asp type asp-drop all" and do "show cap asp | in &amp;lt;ASA IP&amp;gt;" to check that),&lt;BR /&gt;&lt;BR /&gt;BTW does any other service works (SSH/Telnet/HTTP) ?&lt;BR /&gt;&lt;BR /&gt;Send the output of "show run nat " along with all object-groups associated with it.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;BR /&gt;&lt;BR /&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 19:29:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864904#M167372</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-03-18T19:29:07Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864905#M167373</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It seems we are getting ping drops on the ASA outside interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Use an asp-drop capture and also check the &lt;G class="gr_ gr_155 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="155" data-gr-id="155"&gt;syslogs&lt;/G&gt; of the ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Share the output of show cap asp | in outside IP&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 23:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-asa-outside-interface/m-p/2864905#M167373</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-18T23:48:17Z</dc:date>
    </item>
  </channel>
</rss>

