<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA cannot ping internal subinterfaces (DMZs) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-internal-subinterfaces-dmzs/m-p/2576115#M198078</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some&amp;nbsp;questions regarding internal interfaces on the Cisco ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a CISCO 5555-X running version 9.1(3) and a pretty simple configuration. I have an INSIDE and a DMZ, both of them are port-channels but DMZ is working as sub-interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hosts on the DMZ are able to reach all the hosts on the INSIDE and vice versa, I haven´t restricted any traffic yet.But if a host from the INSIDE tries to ping a sub-interface on the ASA (DMZ default-gateway) it gets no response. Even if I ping from the INSIDE interface itself to a DMZ sub-interface I still get no response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;INSIDE: 192.168.254.26&lt;/P&gt;&lt;P&gt;DMZ sub: 13.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA/pri/act# packet-trace input inside icmp 192.168.254.26 8 0 13.1.1.1&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 13.1.1.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;255.255.255.255 identity&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 13.1.1.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;255.255.255.255 identity&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-route) No route to host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this an expected behavior?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be highly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;THANKS!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:19:18 GMT</pubDate>
    <dc:creator>Oscar Bonilla</dc:creator>
    <dc:date>2019-03-12T05:19:18Z</dc:date>
    <item>
      <title>ASA cannot ping internal subinterfaces (DMZs)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-internal-subinterfaces-dmzs/m-p/2576115#M198078</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some&amp;nbsp;questions regarding internal interfaces on the Cisco ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a CISCO 5555-X running version 9.1(3) and a pretty simple configuration. I have an INSIDE and a DMZ, both of them are port-channels but DMZ is working as sub-interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hosts on the DMZ are able to reach all the hosts on the INSIDE and vice versa, I haven´t restricted any traffic yet.But if a host from the INSIDE tries to ping a sub-interface on the ASA (DMZ default-gateway) it gets no response. Even if I ping from the INSIDE interface itself to a DMZ sub-interface I still get no response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;INSIDE: 192.168.254.26&lt;/P&gt;&lt;P&gt;DMZ sub: 13.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA/pri/act# packet-trace input inside icmp 192.168.254.26 8 0 13.1.1.1&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 13.1.1.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;255.255.255.255 identity&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 13.1.1.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;255.255.255.255 identity&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-route) No route to host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this an expected behavior?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be highly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;THANKS!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-internal-subinterfaces-dmzs/m-p/2576115#M198078</guid>
      <dc:creator>Oscar Bonilla</dc:creator>
      <dc:date>2019-03-12T05:19:18Z</dc:date>
    </item>
    <item>
      <title>That's as expected.You can</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-internal-subinterfaces-dmzs/m-p/2576116#M198079</link>
      <description>&lt;P&gt;That's as expected.&lt;/P&gt;&lt;P&gt;You can only ping an ASA interface (assuming it's been allowed) from a host downstream of that interface. Also, you can not ping one ASA interface from another one.&lt;/P&gt;&lt;P&gt;In either case, when talking to an interface directly, the traffic needs to come from a network that's connected to or downstream from that interface.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jan 2015 00:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-internal-subinterfaces-dmzs/m-p/2576116#M198079</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-01-10T00:07:59Z</dc:date>
    </item>
    <item>
      <title>Thank you Marvin, That´s</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-internal-subinterfaces-dmzs/m-p/2576117#M198081</link>
      <description>&lt;P&gt;Thank you Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That´s exactly what I needed to know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a great week!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 15:55:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-internal-subinterfaces-dmzs/m-p/2576117#M198081</guid>
      <dc:creator>Oscar Bonilla</dc:creator>
      <dc:date>2015-01-12T15:55:39Z</dc:date>
    </item>
  </channel>
</rss>

