<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't ping through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944672#M30919</link>
    <description>Here is my running config for the ASA&lt;BR /&gt;&lt;BR /&gt;ciscoasa#show run&lt;BR /&gt;&lt;BR /&gt;: Saved&lt;BR /&gt;&lt;BR /&gt;:&lt;BR /&gt;&lt;BR /&gt;ASA Version 8.4(2)&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;&lt;BR /&gt;names&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 3&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 3&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&lt;BR /&gt;no nameif&lt;BR /&gt;&lt;BR /&gt;no security-level&lt;BR /&gt;&lt;BR /&gt;no ip address&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&lt;BR /&gt;nameif outside&lt;BR /&gt;&lt;BR /&gt;security-level 0&lt;BR /&gt;&lt;BR /&gt;ip address 10.0.0.2 255.255.255.252&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Vlan3&lt;BR /&gt;&lt;BR /&gt;no forward interface Vlan30&lt;BR /&gt;&lt;BR /&gt;nameif dmz-zone&lt;BR /&gt;&lt;BR /&gt;security-level 50&lt;BR /&gt;&lt;BR /&gt;ip address 10.20.30.1 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Vlan30&lt;BR /&gt;&lt;BR /&gt;no nameif&lt;BR /&gt;&lt;BR /&gt;security-level 100&lt;BR /&gt;&lt;BR /&gt;ip address 172.16.1.21 255.255.255.224&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;object network INSIDE-NET&lt;BR /&gt;&lt;BR /&gt;subnet 172.16.1.0 255.255.255.224&lt;BR /&gt;&lt;BR /&gt;object network dmz-server&lt;BR /&gt;&lt;BR /&gt;host 10.20.30.3&lt;BR /&gt;&lt;BR /&gt;object network dmz-server2&lt;BR /&gt;&lt;BR /&gt;host 10.20.30.2&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 10.0.0.1 1&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;access-list icmp extended permit icmp any any&lt;BR /&gt;&lt;BR /&gt;access-list OUTSIDE-DMZ extended permit ip any host 10.20.30.3&lt;BR /&gt;&lt;BR /&gt;access-list OUTSIDE-DMZ extended permit ip any host 10.20.30.2&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;access-group icmp in interface outside&lt;BR /&gt;&lt;BR /&gt;object network dmz-server&lt;BR /&gt;&lt;BR /&gt;nat (dmz-zone,outside) static 205.0.1.1&lt;BR /&gt;&lt;BR /&gt;object network dmz-server2&lt;BR /&gt;&lt;BR /&gt;nat (dmz-zone,outside) static 205.0.1.2&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;class-map inspection-default&lt;BR /&gt;&lt;BR /&gt;class-map icmp-class&lt;BR /&gt;&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;policy-map global-policy&lt;BR /&gt;&lt;BR /&gt;class inspection-default&lt;BR /&gt;&lt;BR /&gt;inspect icmp&lt;BR /&gt;&lt;BR /&gt;policy-map icmp_policy&lt;BR /&gt;&lt;BR /&gt;class icmp-class&lt;BR /&gt;&lt;BR /&gt;inspect icmp&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;dhcpd enable&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 21 Oct 2019 15:30:38 GMT</pubDate>
    <dc:creator>Surtie16</dc:creator>
    <dc:date>2019-10-21T15:30:38Z</dc:date>
    <item>
      <title>Can't ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944652#M30914</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;For some reason I can't ping from my internal network to the external network through the ASA in my network. I have attached a copy of my Packet tracer file. Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 15:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944652#M30914</guid>
      <dc:creator>Surtie16</dc:creator>
      <dc:date>2019-10-21T15:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944657#M30917</link>
      <description>Hi,&lt;BR /&gt;I don't have packet tracer to load your topology, but try entering the command "fixup protocol icmp" to inspect icmp traffic. If that doesn't work, please attach the running configu of your ASA.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Mon, 21 Oct 2019 15:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944657#M30917</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-10-21T15:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944672#M30919</link>
      <description>Here is my running config for the ASA&lt;BR /&gt;&lt;BR /&gt;ciscoasa#show run&lt;BR /&gt;&lt;BR /&gt;: Saved&lt;BR /&gt;&lt;BR /&gt;:&lt;BR /&gt;&lt;BR /&gt;ASA Version 8.4(2)&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;&lt;BR /&gt;names&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 30&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 3&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;&lt;BR /&gt;switchport access vlan 3&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&lt;BR /&gt;no nameif&lt;BR /&gt;&lt;BR /&gt;no security-level&lt;BR /&gt;&lt;BR /&gt;no ip address&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&lt;BR /&gt;nameif outside&lt;BR /&gt;&lt;BR /&gt;security-level 0&lt;BR /&gt;&lt;BR /&gt;ip address 10.0.0.2 255.255.255.252&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Vlan3&lt;BR /&gt;&lt;BR /&gt;no forward interface Vlan30&lt;BR /&gt;&lt;BR /&gt;nameif dmz-zone&lt;BR /&gt;&lt;BR /&gt;security-level 50&lt;BR /&gt;&lt;BR /&gt;ip address 10.20.30.1 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface Vlan30&lt;BR /&gt;&lt;BR /&gt;no nameif&lt;BR /&gt;&lt;BR /&gt;security-level 100&lt;BR /&gt;&lt;BR /&gt;ip address 172.16.1.21 255.255.255.224&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;object network INSIDE-NET&lt;BR /&gt;&lt;BR /&gt;subnet 172.16.1.0 255.255.255.224&lt;BR /&gt;&lt;BR /&gt;object network dmz-server&lt;BR /&gt;&lt;BR /&gt;host 10.20.30.3&lt;BR /&gt;&lt;BR /&gt;object network dmz-server2&lt;BR /&gt;&lt;BR /&gt;host 10.20.30.2&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 10.0.0.1 1&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;access-list icmp extended permit icmp any any&lt;BR /&gt;&lt;BR /&gt;access-list OUTSIDE-DMZ extended permit ip any host 10.20.30.3&lt;BR /&gt;&lt;BR /&gt;access-list OUTSIDE-DMZ extended permit ip any host 10.20.30.2&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;access-group icmp in interface outside&lt;BR /&gt;&lt;BR /&gt;object network dmz-server&lt;BR /&gt;&lt;BR /&gt;nat (dmz-zone,outside) static 205.0.1.1&lt;BR /&gt;&lt;BR /&gt;object network dmz-server2&lt;BR /&gt;&lt;BR /&gt;nat (dmz-zone,outside) static 205.0.1.2&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;class-map inspection-default&lt;BR /&gt;&lt;BR /&gt;class-map icmp-class&lt;BR /&gt;&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;policy-map global-policy&lt;BR /&gt;&lt;BR /&gt;class inspection-default&lt;BR /&gt;&lt;BR /&gt;inspect icmp&lt;BR /&gt;&lt;BR /&gt;policy-map icmp_policy&lt;BR /&gt;&lt;BR /&gt;class icmp-class&lt;BR /&gt;&lt;BR /&gt;inspect icmp&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;dhcpd enable&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Oct 2019 15:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944672#M30919</guid>
      <dc:creator>Surtie16</dc:creator>
      <dc:date>2019-10-21T15:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944680#M30922</link>
      <description>Can you be more specific. What IP address are you pinging from and what IP address are you pinging?&lt;BR /&gt;You do not have a NAT defined for the internal network (172.16.1.x) were you expecting this traffic to be natted? Or does the next hop have a route back to the ASA for this traffic?</description>
      <pubDate>Mon, 21 Oct 2019 15:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944680#M30922</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-10-21T15:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944683#M30925</link>
      <description>pinging from 204.0.1.0 network to the internal network which is the 172.16.1.0 network. Would setting up NAT for this solve this issue?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Oct 2019 15:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944683#M30925</guid>
      <dc:creator>Surtie16</dc:creator>
      <dc:date>2019-10-21T15:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944689#M30927</link>
      <description>So you are actually pinging from outside/external network to inside/internal, not the other way around. Obviously this is a packet tracer lab and not a production network, but is 172.16.1.0 network routable from the outside? Does the next hop of 204.0.1.0 know how to reach 172.16.1.0 network (are there routes define on each hop)? Or is nat required? In which case you'd need to define a static NAT.&lt;BR /&gt;&lt;BR /&gt;Whatever device you are pinging on the 172.16.1.0 network, is it's default gateway the ASA?</description>
      <pubDate>Mon, 21 Oct 2019 15:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944689#M30927</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-10-21T15:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944700#M30929</link>
      <description>&lt;P&gt;Setting up NAT has solved the issue. Thank you so much!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 16:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3944700#M30929</guid>
      <dc:creator>Surtie16</dc:creator>
      <dc:date>2019-10-21T16:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping through ASA</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3945180#M30931</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/921081"&gt;@Surtie16&lt;/a&gt;&amp;nbsp;Ohh Thank you so much for solving the issue. Hope to be more helpfull further.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 09:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-through-asa/m-p/3945180#M30931</guid>
      <dc:creator>JoeSemos27769</dc:creator>
      <dc:date>2019-10-22T09:59:40Z</dc:date>
    </item>
  </channel>
</rss>

