<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic  Many thanks in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529060#M237727</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks Najaf&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jun 2014 20:04:23 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2014-06-07T20:04:23Z</dc:date>
    <item>
      <title>Unable to ping from directly connected Switch to ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529058#M237725</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is setup below&lt;/P&gt;&lt;P&gt;ASA1-----SW------access port to ----ASA2&lt;/P&gt;&lt;P&gt;ASA1 has vlan 4 IP 192.168.1.171&lt;/P&gt;&lt;P&gt;ASA2 has vlan 4 IP 192.168.1.173.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA1 has direct connection to Switch&amp;nbsp; and Switch has direct connection to ASA2.&lt;/P&gt;&lt;P&gt;I can ping from ASA1 to IP&amp;nbsp; 192.168.1.173.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch config is below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch port connected to ASA1 and ASA2 has config below&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport access vlan 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch does not have SVI vlan 4.&lt;/P&gt;&lt;P&gt;From switch i can not ping the IP 192.168.1.171 or 173.&lt;/P&gt;&lt;P&gt;When i config SVI vlan 4 with IP 192.168.1.174 on switch then i can ping IP 192.168.2.171 and .173&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to know is this default behaviour?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:18:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529058#M237725</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T04:18:25Z</dc:date>
    </item>
    <item>
      <title>Hi Mahesh,This is expected</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529059#M237726</link>
      <description>&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;This is expected behavior.&lt;/P&gt;&lt;P&gt;When you have SVI for vlan 4 created on the SW and when you initiate a ping, the ping will be sourced with SVI vlan 4 interface. The switch now knows both the source and destination is on same subnet and hence send a arp broadcast to all vlan 4 ports and ASA responds with its MAC address and ping works.&lt;/P&gt;&lt;P&gt;But when you don't have a SVI for vlan 4 on switch, the ping will be sourced with some other ip address (may be the managment interface of switch) and there should be routing enabled in route this packet to different network.&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jun 2014 19:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529059#M237726</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2014-06-07T19:50:49Z</dc:date>
    </item>
    <item>
      <title> Many thanks</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529060#M237727</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks Najaf&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jun 2014 20:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529060#M237727</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2014-06-07T20:04:23Z</dc:date>
    </item>
    <item>
      <title>Thanks Mahesh for marking</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529061#M237734</link>
      <description>&lt;P&gt;Thanks Mahesh for marking this as correct answer&amp;nbsp;&lt;IMG alt="smiley" height="23" src="https://supportforums.cisco.com/profiles/commons/libraries/ckeditor/plugins/smiley/images/regular_smile.png" title="smiley" width="23" /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jun 2014 20:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-from-directly-connected-switch-to-asa/m-p/2529061#M237734</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2014-06-07T20:16:01Z</dc:date>
    </item>
  </channel>
</rss>

