<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic And test server 1 cannot ping in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769221#M171186</link>
    <description>&lt;P&gt;And test server 1 cannot ping 2 or 3 ?&lt;/P&gt;
&lt;P&gt;If so it comes back to what I said before&lt;/P&gt;
&lt;P&gt;If you cannot ping within the same vlan then is not usually a firewall problem because traffic only goes to the firewall for destination IPs in different subnets.&lt;/P&gt;
&lt;P&gt;Assuming the IP address, subnet mask information is consistent it sounds like a vlan issue.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2015 20:26:50 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2015-10-28T20:26:50Z</dc:date>
    <item>
      <title>Firewall VLAN issue</title>
      <link>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769218#M171183</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a server vlan 10.4.x.x with over 200 servers but i wanted one application in its own vlan. &amp;nbsp;So i created vlan 10.17.x.x&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The servers are now seperated by a firewall&lt;/P&gt;
&lt;P&gt;i moved a first test server across and put in the firewall rules on the cisco asa&amp;nbsp;&lt;/P&gt;
&lt;P&gt;# NO problems at all - the 10.4.x.x. server can ping the 10.17.x.x server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;so i moved a second test server and put it into the same rule but the 10.4.x.x servers cant see it&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The firewall can ping test server 1 but not the second test server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;the bit i have no control over is:&lt;/P&gt;
&lt;P&gt;server team looks after the servers on both 10.4.x.x. and 10.17.x.x networks - i just provide the network and firewall infrastructure&lt;/P&gt;
&lt;P&gt;they say that test server 2 is pinging ok on the box&lt;/P&gt;
&lt;P&gt;test server 1 cant see test server 2 even though they are on the same subnet&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;- only thing i can think of is that test server 1 and test server 2 might be sitting on different chassis but still both on the same 10.4.x.x network&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;any ideas are welcome&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769218#M171183</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2019-03-12T06:48:14Z</dc:date>
    </item>
    <item>
      <title>Kevin</title>
      <link>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769219#M171184</link>
      <description>&lt;P&gt;Kevin&lt;/P&gt;
&lt;P&gt;What do the server team mean when they say test server 2 is pinging ok on the box.&lt;/P&gt;
&lt;P&gt;If you cannot ping between the test servers then rather than concentrate on the firewall can you -&lt;/P&gt;
&lt;P&gt;1) verify the servers are both allocated into your new vlan&lt;/P&gt;
&lt;P&gt;2) verify they are in the same IP subnet with the same subnet mask.&lt;/P&gt;
&lt;P&gt;Also check the default gateways although this should not stop ping between the servers.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 20:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769219#M171184</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-10-28T20:03:13Z</dc:date>
    </item>
    <item>
      <title>Jon,</title>
      <link>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769220#M171185</link>
      <description>&lt;P&gt;Jon,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Both servers are virtual machines sitting in a Dell Chassis. &amp;nbsp;The can login to test server 2 (and also test server 3) and they are up and can ping themselves ok. &amp;nbsp;Test server 2 &amp;amp; 3 can ping each other because they are on the same chassis&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;test server 1 is working ok via the firewall to the corporate network but it cant see the two new servers even though all 3 are on the same subnet and have their own vlan on the firewall interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 20:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769220#M171185</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2015-10-28T20:20:12Z</dc:date>
    </item>
    <item>
      <title>And test server 1 cannot ping</title>
      <link>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769221#M171186</link>
      <description>&lt;P&gt;And test server 1 cannot ping 2 or 3 ?&lt;/P&gt;
&lt;P&gt;If so it comes back to what I said before&lt;/P&gt;
&lt;P&gt;If you cannot ping within the same vlan then is not usually a firewall problem because traffic only goes to the firewall for destination IPs in different subnets.&lt;/P&gt;
&lt;P&gt;Assuming the IP address, subnet mask information is consistent it sounds like a vlan issue.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 20:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769221#M171186</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-10-28T20:26:50Z</dc:date>
    </item>
    <item>
      <title>Got it sorted.  One of the</title>
      <link>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769222#M171187</link>
      <description>&lt;P&gt;Got it sorted.&amp;nbsp; One of the Corporate routers was missing the subnet for the new&amp;nbsp;vlan which sits on the cisco firewall interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Its working fine now&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 16:28:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-vlan-issue/m-p/2769222#M171187</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2015-10-29T16:28:09Z</dc:date>
    </item>
  </channel>
</rss>

