<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't Ping Remote VPN Users in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291311#M310767</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It need not be just ICMP, from avaya phone are you able to reach inside server over the tunnel(any traffic)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats code is ASA running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you attach "sh run nat" and "sh nat details" output here along with ASA inside IP and pool ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Santhosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Oct 2013 12:28:52 GMT</pubDate>
    <dc:creator>Santhosha Shetty</dc:creator>
    <dc:date>2013-10-22T12:28:52Z</dc:date>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291302#M310755</link>
      <description>&lt;P&gt;I apologize for the stupid question but I am so insanely rusty with ASA firewalls it's completely ridiculous! I have about 24 remote users connecting to our ASA 5510. These users pull an IP address from a DHCP scope setup on the firewall in the 172.16.16.100-172.16.16.250 range. I need to be able to ping these users machines over their VPN tunnels. I was under the impression that adding "same-security-traffic permit intra-interface" would allow this but it doesn't. Do I need an ACL for this? What would it look like? I've attached my running config. Maybe I should add that this firewalls only purpose is for these VPN users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help in advance! You'll save my life!!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:53:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291302#M310755</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2019-03-12T02:53:22Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291303#M310757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Hi David.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Did you try to ping them from ASA directly or from your local network?&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;I am able to ping my remote hosts from my local PC, but not directly from ASA even if I use internal command the patern is not recognized to match crypto map (not sure why to be honest).&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;I think you need specifically direct this traffic via outsite interface by creating the following routing entry:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;route outside 172.16.16.0 255.255.255.0 e.f.g.h 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface you need as well obviously, so don't delete that line &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;I hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Regards &lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Mariusz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 14:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291303#M310757</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2013-10-18T14:35:42Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291304#M310758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like you want one VPN user to be able to ping another VPN user (Eg: 172.16.100.101 to ping 172.16.1.102). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have split tunneling enabled on the tunnel group where the VPN users are connecting (cant check as the tunnel group config is missing in the config)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, would you be able to share the output of "show cry ipsec sa" when 2 VPN users are connected to the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Amitashwa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 15:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291304#M310758</guid>
      <dc:creator>amitaaga</dc:creator>
      <dc:date>2013-10-18T15:00:28Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291305#M310760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are these windows machines you are trying to ping?&amp;nbsp; Before going to deep into troubleshooting the config I would disable the windows firewall on the PC and then try pinging.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 20:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291305#M310760</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-10-18T20:13:17Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291306#M310761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mariusz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to ping them directly from the ASA. None of my internal traffic is routed to this firewall. This firewall is only for external connections to one of our internal networks. I'll directly connect my laptop to one of my unused interfaces and test it that way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have &lt;EM&gt;route outside 0.0.0.0 0.0.0.0 e.f.g.h 1&lt;/EM&gt; in place. Isn't that a default route and would include the traffic for 172.16.16.0/24?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 16:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291306#M310761</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-21T16:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291307#M310763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amitashwa,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not trying to ping from one VPN user to another. I just want to be able to ping them from the firewall, entirely for troubleshooting purposes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, we don't have split tunneling enabled. The units I am trying to ping are Avaya VPN desktop phones and do not need this feature. I apologize for for not having the tunnel group config. All of our users are local to the firewall and I was trying to protect their usernames and missed that config when I copied and pasted. If you are still interested:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group avaya type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group avaya general-attributes&lt;/P&gt;&lt;P&gt; address-pool AvayaPool&lt;/P&gt;&lt;P&gt; default-group-policy avaya&lt;/P&gt;&lt;P&gt;tunnel-group avaya ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *****&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is the output you requested for two connected VPN users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 16:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291307#M310763</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-21T16:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291308#M310764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are Avaya VPN desktop phones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 16:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291308#M310764</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-21T16:41:28Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291309#M310765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please follow these steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Ensure the vpn users are connected successfully. Try and PING ASA inside IP address from remote user machine over vpn tunnel. Are these PING successful? If yes then proceed with below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. While you generate traffic destined to active remote vpn users ensure you source it from inside intrface like "ping inside &lt;REMOTE vpn="" user="" assigned="" ip="" address=""&gt;"&lt;/REMOTE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you&amp;nbsp; have issues with just accessing ASA inside IP addess, then&amp;nbsp; please paste "sh run nat"&lt;SPAN style="font-size: 10pt;"&gt; output &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; here for further review and if ASA is running post 8.3&amp;nbsp; append "no-proxy-arp route-lookup" to the corresponding NAT-EXEMPT(no nat ) rule.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are vpn users able to PING ASA inside resource including INSIDE IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Santhosh Shetty&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 16:51:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291309#M310765</guid>
      <dc:creator>Santhosha Shetty</dc:creator>
      <dc:date>2013-10-21T16:51:08Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291310#M310766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Santhosha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply and help. I am unable to ping from the remote user machine. It is an Avaya VPN phone and doesn't offer an option to ping unfortunately. I do know that they respond to pings, however.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 18:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291310#M310766</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-21T18:23:20Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291311#M310767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It need not be just ICMP, from avaya phone are you able to reach inside server over the tunnel(any traffic)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats code is ASA running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you attach "sh run nat" and "sh nat details" output here along with ASA inside IP and pool ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Santhosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 12:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291311#M310767</guid>
      <dc:creator>Santhosha Shetty</dc:creator>
      <dc:date>2013-10-22T12:28:52Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291312#M310769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you examined the ASA logs while pinging the AVAYA phones? Do you see any deny packets, or something that could be preventing the flow of traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the sake of testing could you issue the command &lt;STRONG&gt;management-access inside&lt;/STRONG&gt; and then test to see if you get a response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that doesn't work could you add the command &lt;STRONG&gt;sysopt connection permit-vpn&lt;/STRONG&gt; and then test.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 12:54:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291312#M310769</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-10-22T12:54:30Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291313#M310770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the ASA CLI I pinged 172.16.16.129. While pinging that the ASDM logs (in debugging) didn't show any denied packets. It just shows the ICMP session being built then torn down. Are there better logs to look at?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the other two commands without any luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 16:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291313#M310770</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-23T16:45:41Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291314#M310771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would probably try to capture the ICMP traffic on your VPN ASA local interface and see if any ICMP return messages are coming from the VPN connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list PHONE-ICMP-CAP permit icmp any 172.16.16.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list PHONE-ICMP-CAP permit icmp 172.16.16.0 255.255.255.0 any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;capture PHONE-ICMP-CAP type raw-data access-list PHONE-ICMP-CAP interface inside buffer 1000000 circular-buffer&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try to ping some of them phones&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show capture PHONE-ICMP-CAP &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and see if any replys are showing past the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To remove the capture use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no capture PHONE-ICMP-CAP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no access-list PHONE-ICMP-CAP permit icmp any 172.16.16.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no access-list PHONE-ICMP-CAP permit icmp 172.16.16.0 255.255.255.0 any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 16:57:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291314#M310771</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-23T16:57:58Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291315#M310773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JouniForss,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the detailed instructions. Here is what I got when I tried to ping two different IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show capture PHONE-ICMP-CAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9 packets captured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1: 11:42:50.462225 10.128.0.2 &amp;gt; 172.16.16.118: icmp: echo request &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 2: 11:42:50.521945 172.16.16.118 &amp;gt; 10.128.0.2: icmp: echo reply &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 3: 11:43:03.820422 10.128.0.2 &amp;gt; 172.16.16.118: icmp: echo request &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 4: 11:43:03.878967 172.16.16.118 &amp;gt; 10.128.0.2: icmp: echo reply &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 5: 11:43:08.261628 10.128.0.2 &amp;gt; 172.16.16.118: icmp: echo request &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 6: 11:43:08.322905 172.16.16.118 &amp;gt; 10.128.0.2: icmp: echo reply &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 7: 11:43:18.773565 10.128.0.2 &amp;gt; 172.16.16.246: icmp: echo request &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 8: 11:44:13.093012 10.128.0.2 &amp;gt; 172.16.16.246: icmp: echo request &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 9: 11:44:45.288833 10.128.0.2 &amp;gt; 172.16.16.246: icmp: echo request &lt;/P&gt;&lt;P&gt;9 packets shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mariusz Bochen suggested pinging from inside the network but the network wasn't setup to allow that. I added routes internally to allow traffic to this firewall from my workstation, so I can ping from there instead of the firewall. From the above output pings 1 and 3 came from the firewall directly. But the firewall shows they timeout. Ping 5 is from my machine and it showed a reply. 7, 8, and 9 are from my machine as well but they timeout. Something must be wrong with that phone (.246). So that raises two questions. Why does the ASA show a timeout when in fact there is a response? And why is one phone confirmed connected to the VPN but not passing traffic? (I've actually confirmed a couple of phones are like this.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 17:58:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291315#M310773</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-23T17:58:36Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291316#M310774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest trying to connect using a PC with the client installed, we can take captures, also, please make sure to enable Nat-t as per a previous post and verify the&lt;/P&gt;&lt;P&gt;show crypto ipsec sa output to check encrypted and decrypted traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 18:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291316#M310774</guid>
      <dc:creator>andduart</dc:creator>
      <dc:date>2013-10-23T18:26:05Z</dc:date>
    </item>
    <item>
      <title>Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291317#M310775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Santhosha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm just now learning some of the phones can connect to an inside server and some can not. They are programmed to connect to our PBX server inside of our network once they establish a VPN connection. All of them can connect to the VPN successfully but 4 of them are unable to connect to the call server once connected to the VPN. I am unaware of how to test them to see if they can connect to any other servers. I have tested to see if the owners of these phones can connect using the IPSec VPN client on their laptops, which they can, as well as ping the the call server. Is that what you are asking?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have version 8.2 running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.128.0.11 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool AvayaPool 172.16.16.100-172.16.16.250 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# show run nat&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list NO_NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I couldn't get "show nat details" to work but I got "show nat"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface inside:&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any management any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAT exempt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any management 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAT exempt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any outside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAT exempt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 28572, untranslate_hits = 946731&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any outside 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAT exempt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any inside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAT exempt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any inside 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAT exempt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 19:41:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291317#M310775</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-23T19:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291318#M310776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andres,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to connect using the client installed on a PC. I was able to ping the remote IP from my local machine. I was also able to ping the PBX server (inside server) from the remote machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe NAT-T was already enabled. It doesn't show up in the configs? I ran crypto isakmp nat-traversal 30 and that shows up in the running-config (maybe because it's not a default setting). That didn't seem to resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output for "show crypto ipsec sa" is attached. Traffic doesn't look like it's getting encrypted or decrypted to one of the problem users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 20:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291318#M310776</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-23T20:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291319#M310777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Thank u for the replies, quick questions:&lt;BR /&gt;Is the problem found with all your users at a time to ping from the internal network to your remote clients or with some of them?&lt;BR /&gt;&lt;BR /&gt;Is the problem happening if you test this connecting with the vpn client installed on the pc?&lt;BR /&gt;&lt;BR /&gt;Did you have this working before? If yes, have you made changes?&lt;BR /&gt;&lt;BR /&gt;Could you send the show run tunnel-group 2: show run group-policy (with the one used)&lt;BR /&gt;&lt;BR /&gt;Show ip&lt;BR /&gt;&lt;BR /&gt;Show run nat&lt;BR /&gt;&lt;BR /&gt;Show run all sysopt&lt;BR /&gt;&lt;BR /&gt;That will help a lot&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Coukd you send the&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Oct 2013 01:10:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291319#M310777</guid>
      <dc:creator>andduart</dc:creator>
      <dc:date>2013-10-24T01:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291320#M310778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andres,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The original problem was that I was unable to ping any of my remote VPN phones connected to the firewall. After I setup some routes from the internal network to this firewall I was able to start pinging from the inside network and not directly from the firewall. This is thanks to the suggestions made earlier. (Reminder, this firewall's only purpose is to connect our Avaya VPN phones to it and give them access to the VLAN that our PBX server lives on. So me having access to any other interface besides the managment was not in the orginal plans.) After making that change I am able to ping most of these phones. Once I started pinging phones I realized at least 4 of them don't respond to pings. After further investigation I have found that these phones are connecting to the VPN but traffic is NOT being passed after the connection is established. Traffic is not getting encrypted and decrypted and I of course, can not ping them. NAT-T is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem does not occur with the VPN client. I can ping the PBX server from the VPN client just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of these users had this working before. They are all new users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The requested output has been attached!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much for the help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Oct 2013 15:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291320#M310778</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-10-24T15:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Ping Remote VPN Users</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291321#M310779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can make sure that the phones are connecting to the same groups, please verify this by using the show vpn-sessiondb remote (or ra depending on the version)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They should use the same policies as the others, if they look ok we will need to start with some TS for them by verifying differences in their locations, test them in a different one in case traffic is not allowed.....etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Oct 2013 19:41:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-vpn-users/m-p/2291321#M310779</guid>
      <dc:creator>andduart</dc:creator>
      <dc:date>2013-10-24T19:41:34Z</dc:date>
    </item>
  </channel>
</rss>

