<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ping to FTD interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ping-to-ftd-interface/m-p/3951664#M23906</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I am having issues pinging my FTD internal interfaces. I can actually ping WAN interface, no issue there. But for LAN interface packet tracer says "no route". I can ping the hosts inside the LAN. There are no specific ICMP rules in Device Platform Policy on FMC. Any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.50.31.97/27 is my LAN interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trace to host inside LAN:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; packet-tracer input WAN icmp 10.11.28.169 0 0 10.50.31.97&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: WAN&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-route) No route to host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; packet-tracer input WAN icmp 10.11.28.169 0 0 10.50.31.98&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.50.31.98 using egress ifc LAN&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;..etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trace to WAN interface:&lt;/P&gt;&lt;P&gt;&amp;gt; packet-tracer input WAN icmp 10.11.28.169 0 0 10.11.39.106&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.11.39.106 using egress ifc identity&lt;/P&gt;&lt;P&gt;..etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Nov 2019 10:24:02 GMT</pubDate>
    <dc:creator>Moon1998</dc:creator>
    <dc:date>2019-11-01T10:24:02Z</dc:date>
    <item>
      <title>Ping to FTD interface</title>
      <link>https://community.cisco.com/t5/network-security/ping-to-ftd-interface/m-p/3951664#M23906</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I am having issues pinging my FTD internal interfaces. I can actually ping WAN interface, no issue there. But for LAN interface packet tracer says "no route". I can ping the hosts inside the LAN. There are no specific ICMP rules in Device Platform Policy on FMC. Any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.50.31.97/27 is my LAN interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trace to host inside LAN:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; packet-tracer input WAN icmp 10.11.28.169 0 0 10.50.31.97&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: WAN&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-route) No route to host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; packet-tracer input WAN icmp 10.11.28.169 0 0 10.50.31.98&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.50.31.98 using egress ifc LAN&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;..etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trace to WAN interface:&lt;/P&gt;&lt;P&gt;&amp;gt; packet-tracer input WAN icmp 10.11.28.169 0 0 10.11.39.106&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.11.39.106 using egress ifc identity&lt;/P&gt;&lt;P&gt;..etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 10:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-to-ftd-interface/m-p/3951664#M23906</guid>
      <dc:creator>Moon1998</dc:creator>
      <dc:date>2019-11-01T10:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Ping to FTD interface</title>
      <link>https://community.cisco.com/t5/network-security/ping-to-ftd-interface/m-p/3951669#M23909</link>
      <description>Hi,&lt;BR /&gt;That is to be expected. An FTD/ASA only responds to ICMP traffic sent to the interface that traffic comes in on. So you cannot ping from the WAN interface through the firewall to LAN interface, that's by design.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Fri, 01 Nov 2019 10:40:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-to-ftd-interface/m-p/3951669#M23909</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-11-01T10:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Ping to FTD interface</title>
      <link>https://community.cisco.com/t5/network-security/ping-to-ftd-interface/m-p/3951672#M23917</link>
      <description>&lt;P&gt;Ah, missed that &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 10:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-to-ftd-interface/m-p/3951672#M23917</guid>
      <dc:creator>Moon1998</dc:creator>
      <dc:date>2019-11-01T10:45:13Z</dc:date>
    </item>
  </channel>
</rss>

