<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Are they all in the same in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753395#M192430</link>
    <description>&lt;P&gt;Are they all in the same subnet?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT:&lt;/STRONG&gt; they are obviously not since they are in different VLANS........ apologies&lt;/P&gt;&lt;P&gt;Does the ASA have a route to the PC subnet??&lt;/P&gt;</description>
    <pubDate>Tue, 25 Aug 2015 04:41:10 GMT</pubDate>
    <dc:creator>Andre Neethling</dc:creator>
    <dc:date>2015-08-25T04:41:10Z</dc:date>
    <item>
      <title>Why cannot ping ASA ?</title>
      <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753390#M192416</link>
      <description>&lt;P&gt;Hi It is strange that the PC cannot ping the ASA.&amp;nbsp;The topology is like this ASA(inside)---DeviceA----PC. the ASA can ping PC and DeviceA, but PC cannot ping ASA. When PC ping ASA, we can see message of debug icmp(debug icmp track 255 in the ASA) from the PC. The DeviceA can also ping both ASA and PC. I check the ASA config, which does not any limit to icmp. Anyone can give some suggestion ? Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753390#M192416</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2019-03-12T06:29:25Z</dc:date>
    </item>
    <item>
      <title>Hello Showipospf, The command</title>
      <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753391#M192420</link>
      <description>&lt;P&gt;Hello Showipospf,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The command that controls the ICMP traffic to the box is the ICMP command. That command works in the same fashion as an ACL if you have an allow on the interface that will add an explicit deny at the end. With the show run ICMP you can confirm if the traffic is allowed or at least not denied.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can also create a capture and confirm if the firewall is sending the reply. The command will be something like this. Capture test interface inside match ICMP host (ASA IP) host (client IP).&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can see the result with the show capture test and remove with the command no cap test.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see the reply been sent out then you can get the&amp;nbsp;ASA of the equation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Jose Orozco.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 17:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753391#M192420</guid>
      <dc:creator>joseoroz</dc:creator>
      <dc:date>2015-08-24T17:10:42Z</dc:date>
    </item>
    <item>
      <title>Thank you so much for your</title>
      <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753392#M192426</link>
      <description>&lt;P&gt;Thank you so much for your reply. I did that based on what you said. The ASA did not send reply to PC, but the ASA can send reply to the DeviceA if the DeviceA ping ASA.&amp;nbsp;Why ASA did not send reply to the PC &amp;nbsp;?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 17:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753392#M192426</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2015-08-24T17:54:53Z</dc:date>
    </item>
    <item>
      <title>Hello showipospf,Would you be</title>
      <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753393#M192427</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;A about="/users/showipospf" class="username" datatype="" href="https://supportforums.cisco.com/users/showipospf" property="foaf:name" title="View user profile." typeof="sioc:UserAccount" lang=""&gt;showipospf&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;Would you be so kind to post the output from the show run ICMP command and the result of the packet tracer. Please also confirm that when you ping the ASA you are pining the local interface because if you ping a remote one the firewall is not going to reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jose Orozco.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 22:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753393#M192427</guid>
      <dc:creator>joseoroz</dc:creator>
      <dc:date>2015-08-24T22:22:59Z</dc:date>
    </item>
    <item>
      <title>Hi JoseThanks for your reply.</title>
      <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753394#M192429</link>
      <description>&lt;P&gt;Hi Jose&lt;/P&gt;&lt;P&gt;Thanks for your reply. I can do some test and post it tomorrow. The DeviceA is Layer 3 switch(maybe it include other device in ping path, that is why I call it DeviceA).&amp;nbsp;Before I left office, I did a test where i plug PC into another port of the DeviceA. The port has the same vlan with&amp;nbsp;the port which is physically connected with ASA inside interface. then&amp;nbsp;PC can ping ASA inside interface. Now we say the issue is in the DeviceA instead of ASA, do you think so ？&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 00:57:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753394#M192429</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2015-08-25T00:57:31Z</dc:date>
    </item>
    <item>
      <title>Are they all in the same</title>
      <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753395#M192430</link>
      <description>&lt;P&gt;Are they all in the same subnet?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT:&lt;/STRONG&gt; they are obviously not since they are in different VLANS........ apologies&lt;/P&gt;&lt;P&gt;Does the ASA have a route to the PC subnet??&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 04:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753395#M192430</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-08-25T04:41:10Z</dc:date>
    </item>
    <item>
      <title>Since you didn't see the</title>
      <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753396#M192431</link>
      <description>&lt;P&gt;Since you didn't see the packet going out from the firewall there are a couple of scenarios that I can think:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-As Andre said the firewall&amp;nbsp;doesn't&amp;nbsp;have a route to the network and the traffic is been sent to the default gateway.&lt;/P&gt;&lt;P&gt;2.-The firewall has a route to the destination network but is not able to communicate to the next hop. When the firewall doesn't have an entry for the next hop the packet is not sent out of the interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you have confirmed t hat the packet is sent out to the client if its still not getting to it then you will need to check the SW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jose Orozco.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 15:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753396#M192431</guid>
      <dc:creator>joseoroz</dc:creator>
      <dc:date>2015-08-25T15:30:31Z</dc:date>
    </item>
    <item>
      <title>Thank you all for your reply.</title>
      <link>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753397#M192432</link>
      <description>&lt;P&gt;Thank you all for your reply. The DeviceA contains several devices, one of them is layer2 Pola. After we re-configured it, ping is Ok, Thank you again&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 21:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cannot-ping-asa/m-p/2753397#M192432</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2015-08-25T21:09:28Z</dc:date>
    </item>
  </channel>
</rss>

