<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Did you enable ICMP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818290#M178023</link>
    <description>&lt;P&gt;Did you enable ICMP inspection in your service policy rules under default inspection traffic?&lt;/P&gt;
&lt;P&gt;Have you tried to ping hosts on the other side of the interface? And not the interface it's self?&lt;/P&gt;</description>
    <pubDate>Wed, 11 Nov 2015 05:35:00 GMT</pubDate>
    <dc:creator>Andre Neethling</dc:creator>
    <dc:date>2015-11-11T05:35:00Z</dc:date>
    <item>
      <title>can't ping asa sub interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818289#M178018</link>
      <description>&lt;P style="margin: 0in 0in 8pt;"&gt;I am not able ping ASA 5505 running 8.2.5 sub interface. The traffic is passing thru the interface but not able to ping asa interfaces.&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.13&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 13&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif ESXHosts&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.13.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.14&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 14&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif Ranger&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.14.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.18&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 18&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif Clients1&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.18.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.19&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 19&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif Clients2&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.19.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.29&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 29&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif DCHosts&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.29.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.80&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 80&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif AIXPublic&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.80.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.81&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 81&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif AIXPrivate&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.81.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.82&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 82&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif Temp1&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.82.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;interface GigabitEthernet0/1.83&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;vlan 83&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;nameif Temp2&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;ip address 10.10.83.254 255.255.255.0&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;!&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;**** I have setup the same-security-traffic&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;same-security-traffic permit inter-interface&lt;/P&gt;
&lt;P style="margin: 0in 0in 8pt;"&gt;same-security-traffic permit intra-interface&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:52:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818289#M178018</guid>
      <dc:creator>abhongi01</dc:creator>
      <dc:date>2019-03-12T06:52:07Z</dc:date>
    </item>
    <item>
      <title>Did you enable ICMP</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818290#M178023</link>
      <description>&lt;P&gt;Did you enable ICMP inspection in your service policy rules under default inspection traffic?&lt;/P&gt;
&lt;P&gt;Have you tried to ping hosts on the other side of the interface? And not the interface it's self?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 05:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818290#M178023</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-11-11T05:35:00Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818291#M178028</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Could you please check &amp;nbsp;the output of 'show run icmp' from the ASA. Please provide the output here.&lt;/P&gt;
&lt;P&gt;try adding 'icmp permit &amp;lt;source-ip&amp;gt; &amp;lt;255.255.255.255&amp;gt; &amp;lt;sub-interface-name&amp;gt;'&lt;/P&gt;
&lt;P&gt;Please let me know if ping works after adding this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 06:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818291#M178028</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-11T06:49:55Z</dc:date>
    </item>
    <item>
      <title>Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818292#M178035</link>
      <description>&lt;P&gt;Akshay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is my icmp commands..&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ciscoasa# show run icmp &lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any AIXPrivate&lt;BR /&gt;icmp permit any ESXHosts&lt;BR /&gt;icmp permit 10.10.0.0 255.255.0.0 echo-reply Ranger&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Andre..&lt;/P&gt;
&lt;P&gt;Here is my inspect config&lt;/P&gt;
&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect ip-options &lt;BR /&gt;&amp;nbsp; inspect icmp &lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am able to ping host on other network.. just not the gateway.. which is my ASA subinterfaces..&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 15:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818292#M178035</guid>
      <dc:creator>abhongi01</dc:creator>
      <dc:date>2015-11-11T15:05:46Z</dc:date>
    </item>
    <item>
      <title>I don't think the asa will</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818293#M178038</link>
      <description>&lt;P&gt;I don't think the asa will allow icmp to the interface. If you can ping the hosts, why would you want to ping the interface? You already have traffic successfully traversing the subinterfaces.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 15:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818293#M178038</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-11-11T15:14:00Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818294#M178042</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;As i had mentioned in my last comment, please add the below command. As you have already configured 'permit icmp' then you need to explicitly allow all the source ips from which you need to allo pings to your interface ip or rest of the ip for interface pings would be implicitely dropped. Therefore :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;icmp permit &amp;lt;source-ip(from whrere you are pinging sub-interface)&amp;gt; 255.255.255.255 &amp;lt;sub-interface-name&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You have only configured :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;cmp permit any AIXPrivate&lt;BR /&gt;&lt;SPAN&gt;icmp permit any ESXHosts&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;icmp permit 10.10.0.0 255.255.0.0 echo-reply Ranger&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;- any body is allowed to ping from&amp;nbsp;AIXPrivate&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;-&amp;nbsp;any body is allowed to ping from &lt;SPAN&gt;ESXHosts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;- Only echo-reply is allowed when ping is initiated from ASA with Ranger as source interface.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Akshay Rastogi&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 15:19:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-sub-interfaces/m-p/2818294#M178042</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-11T15:19:24Z</dc:date>
    </item>
  </channel>
</rss>

