<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How did you knkow that your in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813288#M175066</link>
    <description>&lt;P&gt;How did you know that your edge router is ???&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;10.227.79.129 &lt;/SPAN&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 10 Nov 2015 08:20:19 GMT</pubDate>
    <dc:creator>saif musa</dc:creator>
    <dc:date>2015-11-10T08:20:19Z</dc:date>
    <item>
      <title>from asa not able to ping ISP edge router(hence not able to use ip SLA)</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813287#M175065</link>
      <description>&lt;P&gt;AS we are using firewall .our link is up and working fine&amp;nbsp; but we&amp;nbsp; are not able to ping aur edge router beacause of that we are not able to use IP sla. basicly ip sla use icmp to ping&amp;nbsp; edge router&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;kindly help regarding same&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813287#M175065</guid>
      <dc:creator>Sipl_24034</dc:creator>
      <dc:date>2019-03-12T06:51:37Z</dc:date>
    </item>
    <item>
      <title>How did you knkow that your</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813288#M175066</link>
      <description>&lt;P&gt;How did you know that your edge router is ???&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;10.227.79.129 &lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 10 Nov 2015 08:20:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813288#M175066</guid>
      <dc:creator>saif musa</dc:creator>
      <dc:date>2015-11-10T08:20:19Z</dc:date>
    </item>
    <item>
      <title>Hi there,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813289#M175067</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;From the configuration, i could see that next of the ASA is 10.153.66.2 and 10.153.67.2. Please check if icmp is allowed on your edge router 10.227.79.129. Also check if it is reachable from your next hop 10.153.66.2 ISP.&lt;/P&gt;
&lt;P&gt;there is no icmp permit or deny configured on ASA that means it is allowed bydefault. So no issue.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 08:59:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813289#M175067</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-10T08:59:07Z</dc:date>
    </item>
    <item>
      <title>Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813290#M175068</link>
      <description>&lt;P&gt;Akshay,&lt;/P&gt;
&lt;P&gt;First, chick if you can ping you next hop router from inside your ASA. If so, then you can use it (( 10.153.67.2 )) for sla monitoring perpouses.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 09:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813290#M175068</guid>
      <dc:creator>saif musa</dc:creator>
      <dc:date>2015-11-10T09:27:41Z</dc:date>
    </item>
    <item>
      <title>Hi Saif,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813291#M175069</link>
      <description>&lt;P&gt;Hi Saif,&lt;/P&gt;
&lt;P&gt;I guess, he has mentioned that the link is up and working fine. I believe the traffic is fine but icmp might not be allowed on the edge router. That is why i had mentioned that check from the next hop(which is ISP) to check if from there he is able to ping or not. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 09:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813291#M175069</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-10T09:31:34Z</dc:date>
    </item>
    <item>
      <title>Dear Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813292#M175070</link>
      <description>&lt;P&gt;Dear Akshay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for quick responce ..&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As i observed&amp;nbsp; i can able to ping my&amp;nbsp; edge router from 10.153.66.2 .even i can able to ping edge router from my lan .&lt;/P&gt;
&lt;P&gt;problem is that i am not able to ping router from asa ..&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 09:04:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813292#M175070</guid>
      <dc:creator>Sipl_24034</dc:creator>
      <dc:date>2015-11-11T09:04:14Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813293#M175071</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please share the output of 'show run icmp'. Please add the below command and check of it works:&lt;/P&gt;
&lt;P&gt;icmp permit &lt;SPAN&gt;10.227.79.129 255.255.255.255 &amp;lt;outside-interface-nameif&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Akshay Rastogi&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 09:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813293#M175071</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-11T09:34:01Z</dc:date>
    </item>
    <item>
      <title>dear Akshay ,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813294#M175072</link>
      <description>&lt;P&gt;dear Akshay ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;as you said i given icmp permit command.but i found after this commdn even i cant ping my router 10.153.66.2&lt;/P&gt;
&lt;P&gt;icmp command output&lt;/P&gt;
&lt;P&gt;sh run icmp&lt;/P&gt;
&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit host 10.227.79.129 outside1&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 06:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813294#M175072</guid>
      <dc:creator>Sipl_24034</dc:creator>
      <dc:date>2015-11-15T06:43:23Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813295#M175073</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please remove this command. I advised to place it keeping in mind that there might be some other statements are alredy&amp;nbsp;added.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please place captures on Outside interface :&lt;/P&gt;
&lt;P&gt;'cap capi interface outside match icmp any any'&lt;/P&gt;
&lt;P&gt;'cap drop type asp-drop all'&lt;/P&gt;
&lt;P&gt;After adding this, start pings from ASA to your edge routers and then take the output of 'cap capi detail' and 'cap drop detail | in icmp'&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 07:14:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813295#M175073</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-15T07:14:45Z</dc:date>
    </item>
    <item>
      <title>Dear Akshay ,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813296#M175074</link>
      <description>&lt;P&gt;Dear Akshay ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i have given both command but not recived any responce for&lt;/P&gt;
&lt;P&gt;cap drop detail | in icmp&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 08:22:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813296#M175074</guid>
      <dc:creator>Sipl_24034</dc:creator>
      <dc:date>2015-11-15T08:22:17Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813297#M175075</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From the output of the commands suggested by Akshay, I looks like that ICMP is being sent by the ASA but there is no reply to it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now to troubleshoot further you can try following:&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt; As per your configuration, the next hop for all the traffic via outside1 is 10.153.66.2. Check if the next hop device has proper configuration to forward ICMP packet to 10.22.79.129.&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt; The show cap capi details shows that the icmp request is forwarded to device with MAC c08c.c59f.8d51. Check if this is the correct device to which traffic should be forwarded. You can run show arp on ASA and check the MAC-IP mapping for this hardware.&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt; Check if the device with&amp;nbsp;&lt;SPAN&gt;10.22.79.129 has correct reverse route for the traffic being generated by&amp;nbsp;10.153.66.1.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On ASA there is no return traffic recieved so i would suggest you to check the intermediate devices between ASA and the edge router for correct routing and access policies to permit this traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Do share your findings.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;R.S.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 09:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813297#M175075</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-15T09:50:33Z</dc:date>
    </item>
    <item>
      <title>on router provided route for</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813298#M175076</link>
      <description>&lt;P&gt;on router provided route for lan with next hop 10.153.66.1&lt;/P&gt;
&lt;P&gt;and i can ping 10.227.79.129 from my lan as well as router only thing is that not able to ping this ip from ASA.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 10:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813298#M175076</guid>
      <dc:creator>Sipl_24034</dc:creator>
      <dc:date>2015-11-15T10:54:36Z</dc:date>
    </item>
    <item>
      <title>Is there any reverse route on</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813299#M175077</link>
      <description>&lt;P&gt;Is there any reverse route on edge router for 10.153.66.0/30 subnet for replies to ASA ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Rishabh Seth&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 11:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813299#M175077</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-15T11:23:59Z</dc:date>
    </item>
    <item>
      <title>Dear Rishab,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813300#M175078</link>
      <description>&lt;P&gt;Dear Rishab,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;10.153.66.0 Nettwork advertise&amp;nbsp; by relince @there and&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;still i tried to advertised 10.153.66.0 on my router still same problem persist .&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 12:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813300#M175078</guid>
      <dc:creator>Sipl_24034</dc:creator>
      <dc:date>2015-11-15T12:28:13Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813301#M175079</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please configure static route on Router for destination as ASA outside interface. Advertising 66.x network would enble next hops to have that network. However it does not ensure that your edge router is having reverse route for ASA outside interface.&lt;/P&gt;
&lt;P&gt;Please add the route on Edge router for destination IP as ASA outside interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 17:20:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813301#M175079</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-15T17:20:25Z</dc:date>
    </item>
    <item>
      <title>Try to ping the ASA ip from</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813302#M175080</link>
      <description>&lt;P&gt;Try to ping the ASA ip from edge router and take capture on ASA as suggested by Akshay earlier, this would help in figuring out if there are correct routes configured in your network to forward traffic to ASA from edge router.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I think the problem lies outside ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Share your findings.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Rishabh&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 17:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813302#M175080</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-15T17:54:36Z</dc:date>
    </item>
    <item>
      <title>i found  while traceroute</title>
      <link>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813303#M175081</link>
      <description>&lt;P&gt;i found&amp;nbsp; while traceroute from edge taking unusal path. escalated to isp .&lt;/P&gt;
&lt;P&gt;i will come back after isp responce ...&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 05:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/from-asa-not-able-to-ping-isp-edge-router-hence-not-able-to-use/m-p/2813303#M175081</guid>
      <dc:creator>Sipl_24034</dc:creator>
      <dc:date>2015-11-16T05:47:51Z</dc:date>
    </item>
  </channel>
</rss>

