<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Thomas,Your R1 config is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442111#M268056</link>
    <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;Your R1 config is incomplete, so I'm basing this entirely on the ASA config. I would remove the global_access ACL and change the inside_access_in ACL to permit ip any any. Also make sure that the webserver has a default gateway of 192.168.70.10.&lt;/P&gt;&lt;P&gt;Make sure that R1 has the necessary routes to get to 192.168.100.0/24 subnet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also keep in mind that I've seen strange behavior with the ASA in GNS3. It sometimes won't pass traffic like it's supposed to.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Wed, 26 Mar 2014 03:32:16 GMT</pubDate>
    <dc:creator>Mike Williams</dc:creator>
    <dc:date>2014-03-26T03:32:16Z</dc:date>
    <item>
      <title>Unable to ping (or connect) across network through Router/ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442110#M268047</link>
      <description>&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;Guys,&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;I've built a lab in gns3, one router and one ASA, the ASA has an inside, DMZ (with a small network behind it with just 1 server up and running at present) and an outside interface whilst the router has 3 interfaces on 3 subnets that connect a PC in each of the subnets using VMWare.&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;I have attached a screenshot of my topology so that you better understand what I have done and included the config files.&amp;nbsp;&lt;A href="https://www.dropbox.com/s/zjag2pt2dgper9p/topology.png" style="font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;" target="_blank"&gt;https://www.dropbox.com/s/zjag2pt2dgper9p/topology.png&lt;/A&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;Basically, what I am trying to achieve is be able to connect through a pc in say the HR subnet through to the webserver in the DMZ, the webserver is LAMP, which is a pre-built VMWare appliance that runs webservices and it's mainly to just test.&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;I'm obviously missing out somethign simple as I can see it trying to connect through the ASDM log messages. I have changed the firewall rules to reflect this but still no avail.&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;I would appreciate some assistance if someone could spare 5 mins, I would really appreciate it.&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;Thanks&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"&gt;Thomas.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442110#M268047</guid>
      <dc:creator>Thomas McLean</dc:creator>
      <dc:date>2019-03-12T03:59:46Z</dc:date>
    </item>
    <item>
      <title>Hi Thomas,Your R1 config is</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442111#M268056</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;Your R1 config is incomplete, so I'm basing this entirely on the ASA config. I would remove the global_access ACL and change the inside_access_in ACL to permit ip any any. Also make sure that the webserver has a default gateway of 192.168.70.10.&lt;/P&gt;&lt;P&gt;Make sure that R1 has the necessary routes to get to 192.168.100.0/24 subnet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also keep in mind that I've seen strange behavior with the ASA in GNS3. It sometimes won't pass traffic like it's supposed to.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2014 03:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442111#M268056</guid>
      <dc:creator>Mike Williams</dc:creator>
      <dc:date>2014-03-26T03:32:16Z</dc:date>
    </item>
    <item>
      <title>Thanks for the reply Mike, I</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442112#M268062</link>
      <description>&lt;P&gt;Thanks for the reply Mike, I had put static routes from R1 pointing to the ASA and to the correct subnet...I will update the config later, but I am getting deny messages from the ASA basically saying it cannot see the route, as if it's trying to go out the outside interface...I believe it is something that I am doing wrong rather than GNS3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try your suggestion tonight as I did notice last night that GNS3 wouldn't let me launch ASDM until the ASA was reloaded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thomas.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2014 09:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442112#M268062</guid>
      <dc:creator>Thomas McLean</dc:creator>
      <dc:date>2014-03-26T09:01:53Z</dc:date>
    </item>
    <item>
      <title>Here is an update, I'm still</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442113#M268072</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Here is an update, I'm still confused to what I could be doing wrong:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I am chucking everything from the router over to the ASA with the static route below&lt;/P&gt;&lt;P&gt;R1#sh run | in ip route&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 192.168.100.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Below is the interfaces on the ASA.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.0.100 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.100.1 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet2&lt;BR /&gt;&amp;nbsp;nameif DMZ&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.70.10 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group DMZ_access_in in interface DMZ&lt;BR /&gt;access-group global_access global&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Static routes pointing over to the subnet via the DMZ gateway IP (I've also tried 192.168.70.1 with same issues)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;route inside 192.168.10.0 255.255.255.0 192.168.70.10 1&lt;BR /&gt;route inside 192.168.20.0 255.255.255.0 192.168.70.10 1&lt;BR /&gt;route inside 192.168.30.0 255.255.255.0 192.168.70.10 1&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;I can ping the correct places directly from the ASA CLI without issues but when I try it from the ASDM on any interface it returns the dreaded ?????&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# ping 192.168.70.128&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.70.128, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R1#ping 192.168.70.128&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.70.128, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And here is the pictures to ASDM, I have configured the ACL's in that way to prove that all interfaces allow EVERYTHING, I have also tried many other ACL methods but still no luck.&lt;/P&gt;&lt;P&gt;https://www.dropbox.com/s/feacsynralx68ok/ASAIssues.png&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all the help so far everyone but if anyone else can assist I would really appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thomas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2014 20:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-or-connect-across-network-through-router-asa/m-p/2442113#M268072</guid>
      <dc:creator>Thomas McLean</dc:creator>
      <dc:date>2014-03-26T20:42:23Z</dc:date>
    </item>
  </channel>
</rss>

