<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to ping one vlan int to other vlan int FWSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296802#M311288</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the ICMP can you see anything in the ARP table for 190.202.128.201?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show arp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Oct 2013 16:09:53 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-10-09T16:09:53Z</dc:date>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296801#M311286</link>
      <description>&lt;P&gt;I have created two vlan interfaces in my FWSM:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan30&lt;/P&gt;&lt;P&gt; description Internet&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 190.202.128.204 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan500&lt;/P&gt;&lt;P&gt; description Interfaz Interna&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see them in the route table:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 190.202.128.201, outside &lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 190.202.128.200 255.255.255.248 is directly connected, outside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 is directly connected, inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have permitted the traffic icmp in the default class-map:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns maximum-length 512 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect smtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However i'm unable to ping from inside interface to outside interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM-UBV-01# ping inside 190.202.128.201&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 190.202.128.201, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;?????&lt;/P&gt;&lt;P&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have permmitted icmp in both interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alejandro Rodríguez&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296801#M311286</guid>
      <dc:creator>Jose Alejandro Rodriguez Rodriguez</dc:creator>
      <dc:date>2019-03-12T02:49:19Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296802#M311288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the ICMP can you see anything in the ARP table for 190.202.128.201?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show arp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 16:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296802#M311288</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-09T16:09:53Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296803#M311289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I learned it &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM-UBV-01# sh arp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside 190.202.128.201 58bf.eabf.cb40 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eobc 127.0.0.51 0000.1500.0000 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I even has and ACL tha permits anything&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm even unable to ping my outside vlan int &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM-UBV-01# ping inside 190.202.128.204&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 190.202.128.204, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;?????&lt;/P&gt;&lt;P&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here' s my config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM-UBV-01# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;FWSM Version 4.0(4) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname FWSM-UBV-01&lt;/P&gt;&lt;P&gt;domain-name UBV.local&lt;/P&gt;&lt;P&gt;enable password 22hEzYDRd/PSXhZG encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan30&lt;/P&gt;&lt;P&gt; description Internet&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 190.202.128.204 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan500&lt;/P&gt;&lt;P&gt; description Interfaz Interna&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list 101 extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list 101 extended permit icmp any any source-quench &lt;/P&gt;&lt;P&gt;access-list 101 extended permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;access-list 101 extended permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list 101 extended permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;access-group 101 out interface outside&lt;/P&gt;&lt;P&gt;access-group 101 in interface inside&lt;/P&gt;&lt;P&gt;access-group 101 out interface inside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 190.202.128.201 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 1:00:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;username cpsadmin password uOBCikV6i4nTdDHP encrypted privilege 15&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 200.109.233.226 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;http 190.142.129.227 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;service reset no-connection&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns maximum-length 512 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect smtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:2c824700279062c092f17087c47035ef&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i dont specify the source i get the ping:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM-UBV-01# ping 190.202.128.201&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 190.202.128.201, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;&lt;P&gt;FWSM-UBV-01# &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 16:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296803#M311289</guid>
      <dc:creator>Jose Alejandro Rodriguez Rodriguez</dc:creator>
      <dc:date>2013-10-09T16:14:34Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296804#M311292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is your outside &lt;SPAN style="background-color: #ffffff; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;ip address 190.202.128.&lt;STRONG&gt;204&lt;/STRONG&gt; and you are saying that you want to ping 190.202.128.204&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;FWSM-UBV-01# ping inside 190.202.128&lt;STRONG&gt;.201&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Sending 5, 100-byte ICMP Echos to 190.202.128.201, timeout is 2 seconds:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;?????&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;Can you please confirm what you are trying to ping?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 16:16:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296804#M311292</guid>
      <dc:creator>Anas Hijjawi</dc:creator>
      <dc:date>2013-10-09T16:16:32Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296805#M311295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to ping both first my outside address and my MSFC who is &lt;SPAN style="font-size: 10pt;"&gt;190.202.128&lt;/SPAN&gt;&lt;STRONG style="border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;.201&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM-UBV-01# ping inside 190.202.128.204&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 190.202.128.204, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;?????&lt;/P&gt;&lt;P&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i dont specify the source i get the ping, but i suppose its because i'm using the outside iface as source addrress&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM-UBV-01# ping 190.202.128.201 &lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 190.202.128.201, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 16:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296805#M311295</guid>
      <dc:creator>Jose Alejandro Rodriguez Rodriguez</dc:creator>
      <dc:date>2013-10-09T16:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296806#M311297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would probably be better of PINGing from an actual host interface behind the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface (didnt even notice the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface specified on the first readthrough)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If ICMP to &lt;STRONG&gt;"outside"&lt;/STRONG&gt; network doesnt work from an IP address behind&lt;STRONG&gt; "inside"&lt;/STRONG&gt; interface then I would either configure Dynamic PAT for the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; users or configure a route that tells tha the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; network is found behind the &lt;STRONG&gt;"outside" &lt;/STRONG&gt;interface IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice though that a host behind &lt;STRONG&gt;"inside"&lt;/STRONG&gt; wont be able to ICMP to the &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface IP address and host behind &lt;STRONG&gt;"outside"&lt;/STRONG&gt; wont be able to ICMP the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface. This is normal behaviour&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 16:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296806#M311297</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-09T16:28:22Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296807#M311299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://community.cisco.com/people/JouniForss" id="jive-21864416841036801164363" style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; outline: none; color: #000000; font-weight: bold; font-family: Arial, verdana, sans-serif;"&gt;JouniForss&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Notice though that a host behind &lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;"inside"&lt;/STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt; wont be able to ICMP to the &lt;/SPAN&gt;&lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;"outside"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; interface IP address and host behind &lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;"outside" &lt;/STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt;wont be able to ICMP the&amp;nbsp; &lt;/SPAN&gt;&lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;"inside" &lt;/STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt; interface. This is normal behaviour"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;This is precisely what i wanna do but instead of using a host of the inside interface i want to use the svi inside in the FWSM as source of ping, this is because i'm trying to see if PAT works being able to ping to Internet hosts from the inside interface"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;But i'm not able even to ping my own interfaces.....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 16:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296807#M311299</guid>
      <dc:creator>Jose Alejandro Rodriguez Rodriguez</dc:creator>
      <dc:date>2013-10-09T16:39:49Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296808#M311302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not 100% sure about the FWSM but the ASA atleast wont apply NAT configurations for traffic that you generate with the &lt;STRONG&gt;"ping"&lt;/STRONG&gt; command. It just forwards the traffic without NAT applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I confirmed this on the ASA with traffic capture (my public gw IP replaced with 1.1.1.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface Vlan1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; description LAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nameif LAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; security-level 100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; ip address 10.0.10.2 255.255.254.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA(config)# ping LAN 1.1.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type escape sequence to abort.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;?????&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Success rate is 0 percent (0/5)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA(config)# sh capture&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;capture ICMP-CAP type raw-data access-list ICMP-CAP interface WAN [Capturing - 670 bytes]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA(config)# sh capture ICMP-CAP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;5 packets captured&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; 1: 19:46:36.814151&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#10 P0 10.0.10.2 &amp;gt; 1.1.1.1: icmp: echo request&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; 2: 19:46:38.811740&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#10 P0 10.0.10.2 &amp;gt; 1.1.1.1: icmp: echo request&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; 3: 19:46:40.811847&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#10 P0 10.0.10.2 &amp;gt; 1.1.1.1: icmp: echo request&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; 4: 19:46:42.811984&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#10 P0 10.0.10.2 &amp;gt; 1.1.1.1: icmp: echo request&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; 5: 19:46:44.812015&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#10 P0 10.0.10.2 &amp;gt; 1.1.1.1: icmp: echo request&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see I did the capture on the WAN interface and no PAT has been applied to this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 16:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296808#M311302</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-09T16:49:24Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296809#M311304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm so its not possible to ping form inside iface to ouside iface after all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have issued a sh iface and see a lot of packed dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Vlan500 "inside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware is EtherSVI, BW Unknown Speed-Capability, DLY 10 usec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Description: Interfaz Interna&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC address d867.d992.5400, MTU 1500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address 192.168.1.1, subnet mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; Traffic Statistics for "inside":&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 packets input, 0 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 packets output, 68 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4696 packets dropped&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;Interface Vlan500 "inside", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is EtherSVI, BW Unknown Speed-Capability, DLY 10 usec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Description: Interfaz Interna&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC address d867.d992.5400, MTU 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address 192.168.1.1, subnet mask 255.255.255.0&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "inside":&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 packets input, 0 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 packets output, 68 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4696 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even when i have explicitely set an ACL for permit all traffic ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 17:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296809#M311304</guid>
      <dc:creator>Jose Alejandro Rodriguez Rodriguez</dc:creator>
      <dc:date>2013-10-09T17:05:10Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296810#M311306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco firewalls and routers tend to drop traffic all the time mostly because the device next to them has a service/setting enabled that the firewall/router doesnt support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But its a known fact that you cant ping the actual interface IP address from behind another interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the FWSM you should be able to ping any interface IP address configured on the FWSM directly. (Wihtout specifying any interface in the &lt;STRONG&gt;"ping"&lt;/STRONG&gt; command)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From behind some FWSM interface you should only be able to ping the IP address of your interface. Not any other FWSM interface IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 17:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296810#M311306</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-09T17:10:05Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296811#M311308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I beleive Jouni's answer is correct, &lt;SPAN style="font-size: 10pt;"&gt;FWSM will not allow to ping from one vlan to the other vlan gateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Please rate helpful answers&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 18:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296811#M311308</guid>
      <dc:creator>Anas Hijjawi</dc:creator>
      <dc:date>2013-10-09T18:00:21Z</dc:date>
    </item>
    <item>
      <title>Unable to ping one vlan int to other vlan int FWSM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296812#M311309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all. I guess I should figure it out and see how can i test PAT without using icmp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 18:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-one-vlan-int-to-other-vlan-int-fwsm/m-p/2296812#M311309</guid>
      <dc:creator>Jose Alejandro Rodriguez Rodriguez</dc:creator>
      <dc:date>2013-10-09T18:17:16Z</dc:date>
    </item>
  </channel>
</rss>

