<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I believe you can only source in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pinging-from-asa-using-interface-as-source-packet-tracer/m-p/2456782#M238628</link>
    <description>&lt;P&gt;I believe you can only source traffic from ASA the itself on the interface which is the correct egress to the target network (when that target is a connected network).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2014 15:49:04 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-05-08T15:49:04Z</dc:date>
    <item>
      <title>Pinging from ASA using Interface as Source - Packet-Tracer</title>
      <link>https://community.cisco.com/t5/network-security/pinging-from-asa-using-interface-as-source-packet-tracer/m-p/2456781#M238625</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;I have the following Interfaces and routes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.127&lt;BR /&gt;&amp;nbsp;vlan 127&lt;BR /&gt;&amp;nbsp;nameif Vlan127&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.127.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0.128&lt;BR /&gt;&amp;nbsp;vlan 128&lt;BR /&gt;&amp;nbsp;nameif Vlan128&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.128.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0.129&lt;BR /&gt;&amp;nbsp;vlan 129&lt;BR /&gt;&amp;nbsp;nameif Vlan129&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.129.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0.250&lt;BR /&gt;&amp;nbsp;description Vid_Conf&lt;BR /&gt;&amp;nbsp;vlan 250&lt;BR /&gt;&amp;nbsp;nameif vlan250&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.44.250.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172.27.100.160 255.255.252.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 217.x.x.x&lt;BR /&gt;route inside 10.0.0.0 255.0.0.0 172.27.100.10 1&lt;BR /&gt;route inside 172.16.0.0 255.240.0.0 172.27.100.10 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running a packet tracer to see if I can ping one of my inside networks using the vlan interface IP as the source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;packet-tracer input vlan250 icmp 10.44.250.1 8 0 172.27.4.1&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 172.16.0.0 &amp;nbsp; &amp;nbsp; &amp;nbsp;255.240.0.0 &amp;nbsp; &amp;nbsp; inside&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Result:&lt;BR /&gt;input-interface: vlan250&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I be able to use the VLAN250 Interface IP as the source?&lt;/P&gt;&lt;P&gt;If I use another address within that network the packet tracer allows ICMP. See below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;# packet-tracer input vlan250 icmp 10.44.250.10 8 0 172.27.4.1&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 172.16.0.0 &amp;nbsp; &amp;nbsp; &amp;nbsp;255.240.0.0 &amp;nbsp; &amp;nbsp; inside&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Phase: 4&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Phase: 5&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;and so forth...&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pinging-from-asa-using-interface-as-source-packet-tracer/m-p/2456781#M238625</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2019-03-12T04:10:33Z</dc:date>
    </item>
    <item>
      <title>I believe you can only source</title>
      <link>https://community.cisco.com/t5/network-security/pinging-from-asa-using-interface-as-source-packet-tracer/m-p/2456782#M238628</link>
      <description>&lt;P&gt;I believe you can only source traffic from ASA the itself on the interface which is the correct egress to the target network (when that target is a connected network).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 15:49:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pinging-from-asa-using-interface-as-source-packet-tracer/m-p/2456782#M238628</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-08T15:49:04Z</dc:date>
    </item>
  </channel>
</rss>

