<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You probably have an access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-static-routing-issue/m-p/2662124#M196867</link>
    <description>&lt;P&gt;You probably have an access-group on the DMZ interface that does not allow ICMP packets. Also, in order to allow the routing on a stick on an ASA, you need the following :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
    <pubDate>Sat, 21 Feb 2015 17:46:45 GMT</pubDate>
    <dc:creator>Kamal Malhotra</dc:creator>
    <dc:date>2015-02-21T17:46:45Z</dc:date>
    <item>
      <title>ASA static Routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-routing-issue/m-p/2662123#M196866</link>
      <description>&lt;P&gt;We have a Cisco ASA as our Front firewall Connected to&amp;nbsp;internet and&amp;nbsp;DMZ. DMZ is 10.10.0.0 network. I have a router on the DMZ network&amp;nbsp;and want to ping its loop back Interface IP address from a client computer in DMZ. A Client computer&amp;nbsp;in the DMZ uses the ASA as the default gateway.&lt;/P&gt;&lt;P&gt;Static route seems to work when I ping from the ASA to the loopback but when I ping from the Client computer to the loopback address it does not work. The firewall logs say&amp;nbsp;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;SPAN class="cCp_CmdPlain"&gt;"The &lt;/SPAN&gt;ASA&lt;SPAN class="cCp_CmdPlain"&gt; denied any inbound ICMP packet access. By default, all ICMP packets are denied access unless specifically allowed."&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;Configuration&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;ASA - DMZ (Inside) IP address 10.10.0.254&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;SPAN class="cCp_CmdPlain"&gt;Client &amp;nbsp;- 10.10.0.251/24 Default Gateway 10.10.0.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;SPAN class="cCp_CmdPlain"&gt;Router - FA0/0 10.60.0.15 - Loop Back - 172.16.8.21&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-routing-issue/m-p/2662123#M196866</guid>
      <dc:creator>arell1234</dc:creator>
      <dc:date>2019-03-12T05:32:14Z</dc:date>
    </item>
    <item>
      <title>You probably have an access</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-routing-issue/m-p/2662124#M196867</link>
      <description>&lt;P&gt;You probably have an access-group on the DMZ interface that does not allow ICMP packets. Also, in order to allow the routing on a stick on an ASA, you need the following :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2015 17:46:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-routing-issue/m-p/2662124#M196867</guid>
      <dc:creator>Kamal Malhotra</dc:creator>
      <dc:date>2015-02-21T17:46:45Z</dc:date>
    </item>
  </channel>
</rss>

