<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic can't ping remote networks via GRE tunnels between cisco routers in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349844#M344852</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i've installed two ASA in two offices, all works well but from ASA inside interface i cant' ping my remote networks.&lt;/P&gt;&lt;P&gt;The two sites are connected with GRE/IPsec tunnels. From routers i can ping my remote networks (both sides).&lt;/P&gt;&lt;P&gt;I've looked in the forum and seems someone has solved with "route-lookup" as option in the NAT line but i already have this enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;NAT:&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static obj-LAN obj-LAN destination static obj-REMOTE-net obj-REMOTE-net no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;ACL:&lt;/P&gt;&lt;P&gt;access-list ACL-OUTSIDE extended permit ip object obj-REMOTE-net any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Routes are received by an eigrp process: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;D&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [90/14057472] via 194.194.194.1, 0:06:04, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From all hosts behind inside interface i can ping my remote networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks all for help.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicola&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:24:37 GMT</pubDate>
    <dc:creator>na26</dc:creator>
    <dc:date>2019-03-12T02:24:37Z</dc:date>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349844#M344852</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i've installed two ASA in two offices, all works well but from ASA inside interface i cant' ping my remote networks.&lt;/P&gt;&lt;P&gt;The two sites are connected with GRE/IPsec tunnels. From routers i can ping my remote networks (both sides).&lt;/P&gt;&lt;P&gt;I've looked in the forum and seems someone has solved with "route-lookup" as option in the NAT line but i already have this enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;NAT:&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static obj-LAN obj-LAN destination static obj-REMOTE-net obj-REMOTE-net no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;ACL:&lt;/P&gt;&lt;P&gt;access-list ACL-OUTSIDE extended permit ip object obj-REMOTE-net any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Routes are received by an eigrp process: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;D&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [90/14057472] via 194.194.194.1, 0:06:04, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From all hosts behind inside interface i can ping my remote networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks all for help.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicola&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:24:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349844#M344852</guid>
      <dc:creator>na26</dc:creator>
      <dc:date>2019-03-12T02:24:37Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349845#M344853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you trying to do it like this :&lt;/P&gt;&lt;P&gt;ping inside x.x.x.x. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that's the case it's not going to work as the ASA is sending the traffic via the inside interface not being sourced from it. This is a commom missconception.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further IT information.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 14:36:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349845#M344853</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-12T14:36:53Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349846#M344855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i'm trying simply:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping ip_remote&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;N.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 14:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349846#M344855</guid>
      <dc:creator>na26</dc:creator>
      <dc:date>2013-08-12T14:44:33Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349847#M344857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you add &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;management-access inside asa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 16:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349847#M344857</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-12T16:08:36Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349848#M344859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nothing changed. if i try to trace the packet this is the results:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside-g tcp 192.168.1.42 80 192.168.2.31 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 192.168.2.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (inside-g,outside) source static obj-LAN-G obj-LAN-G destination static obj-LAN-BO obj-LAN-BO no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface outside&lt;/P&gt;&lt;P&gt;Untranslate 192.168.2.31/80 to 192.168.2.31/80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside-g&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 18:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349848#M344859</guid>
      <dc:creator>na26</dc:creator>
      <dc:date>2013-08-12T18:28:33Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349849#M344861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Expected Behavior, don't use the ASA interface IP address for Packet-tracer tests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again how are you trying to test this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do a&amp;nbsp; &lt;SPAN style="font-size: 10pt;"&gt;ping ip_remote it will try to use the interface closest to the destination. is the interface closest to the destination the inside interface?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 19:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349849#M344861</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-12T19:09:06Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349850#M344862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, a simple diagram is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host1-LAN1--insideASA1outside--ROUTER1------GREtunnel------ROUTER2--outsideASA2inside---LAN2-host2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i ping host2 from host1 all it's ok.&lt;/P&gt;&lt;P&gt;If i ping host1 from host2 all it's ok.&lt;/P&gt;&lt;P&gt;If i ping host2 from ROUTER1 all it's ok.&lt;/P&gt;&lt;P&gt;If i ping host1 from ROUTER2 all it's ok.&lt;/P&gt;&lt;P&gt;If i ping host2 from ASA1 not works.&lt;/P&gt;&lt;P&gt;If i ping host1 from ASA2 not works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 19:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349850#M344862</guid>
      <dc:creator>na26</dc:creator>
      <dc:date>2013-08-12T19:22:57Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349851#M344863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Facts&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Okey so it's not a problem with ICMP through the ASA, &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;The packet is being generated on the ASA.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="line-height: 0px; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Is traffic over the GRE tunnel including the outside subnets of both ASAs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can you ping from ASA1 ASA 2?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 0px;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 22:34:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349851#M344863</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-12T22:34:58Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349852#M344864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;no from ASA1 i can't ping ASA2 and vice versa and yes outside subnet are routed over GRE tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 06:00:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349852#M344864</guid>
      <dc:creator>na26</dc:creator>
      <dc:date>2013-08-13T06:00:24Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349853#M344865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they can communicate with each other via the outside interface then there should be an issue on the network in between (GRE tunnel)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 06:40:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349853#M344865</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-13T06:40:51Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349854#M344866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would be better to have your addressing scheme and see what you're trying to ping from where. In your packet tracer it looks like you're trying to ping from the asa's inside interface wich won't work. Have you tried to ping just from ASA1 to ASA2? Do both ASA know that traffic to another ASA should go through corresponding ISR? are those ISRs default gateways for each ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 07:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349854#M344866</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-08-13T07:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping remote networks via GRE tunnels between cisco rou</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349855#M344867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/3/0/151037-g_forum.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that the jpg attached can clarify my network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- ISRs are the default gateway for both ASA.&lt;/P&gt;&lt;P&gt;- If i ping ASA2 outside interface from ASA1 all it's ok, same from ASA2 to ASA1&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.2.0/24 from router1 it works&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.1.0/24 from router2 it works&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.3.0/24 from router2 it works&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.2.0/24 from 192.168.1.0 subnet it works&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.2.0/24 from 192.168.3.0 subnet it works&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.1.0/24 from 192.168.2.0 subnet it works&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.3.0/24 from 192.168.2.0 subnet it works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.2.0/24 from ASA1&amp;nbsp; NOT works&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.1.0/24 from ASA2&amp;nbsp; NOT works&lt;/P&gt;&lt;P&gt;- If i ping a host on 192.168.3.0/24 from ASA2&amp;nbsp; NOT works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA1 routing table:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;D&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [90/14057472] via 1.1.1.1, 0:50:28, outside&lt;/P&gt;&lt;P&gt;D&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.6.6.1 255.255.255.248 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [90/14054912] via 1.1.1.1, 0:50:28, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA2 routing table:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;D&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [90/14057472] via 6.6.6.1, 0:01:21, outside&lt;/P&gt;&lt;P&gt;D&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [90/14054912] via 6.6.6.1, 0:01:21, outside&lt;/P&gt;&lt;P&gt;D&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [90/14057472] via 6.6.6.1, 0:01:21, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;N.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 11:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349855#M344867</guid>
      <dc:creator>na26</dc:creator>
      <dc:date>2013-08-13T11:45:36Z</dc:date>
    </item>
    <item>
      <title>can't ping remote networks via GRE tunnels between cisco routers</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349856#M344870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To my understanding there might be two things:&lt;/P&gt;&lt;P&gt;1. ASAs are not the default gateways for their LANs and host, say on site B (where ASA2 sits) doesn't know the route back towards ASA1, when replying to the ICMP.&lt;/P&gt;&lt;P&gt;2. Or in the same situation, ASA2&amp;nbsp; doesn't allow returning ICMP traffic back from the host towards ASA1 outside IP, due to the ACL configuration.&lt;/P&gt;&lt;P&gt;Another thing, is that some NAT rules might be configured on either ASA with no nat exemption for communication between some LAN and oposite ASA's outside IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't really think that you've got one of those things, but to me there should be nothing else preventing this communication having environment that you've got (with all those pings between subnets and ASA's working fine).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 13:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349856#M344870</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-08-13T13:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: can't ping remote networks via GRE tunnels between cisco rou</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349857#M344872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASAs are the default gw for respective LANs. For the point 2 if i trace the packets i can see that their are blocked &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;packet-tracer input inside-g tcp 192.168.1.42 80 192.168.2.31 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Phase: 1&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Subtype: input&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Result: ALLOW&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Config:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Additional Information:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;in&amp;nbsp;&amp;nbsp; 192.168.2.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Phase: 2&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Type: UN-NAT&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Subtype: static&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Result: ALLOW&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Config:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;nat (inside-g,outside) source static obj-LAN-G obj-LAN-G destination static obj-LAN-BO obj-LAN-BO no-proxy-arp route-lookup&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Additional Information:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;NAT divert to egress interface outside&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Untranslate 192.168.2.31/80 to 192.168.2.31/80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Phase: 3&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Subtype:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Result: DROP&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Config:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Implicit Rule&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Result:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;input-interface: inside-g&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;input-status: up&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;input-line-status: up&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;output-interface: outside&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;output-status: up&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;output-line-status: up&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Action: drop&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.1.42 is the ASA1 inside IP address. But i've an explicit ACL that permits ALL traffic from 192.168.1.0/24.&lt;/P&gt;&lt;P&gt;I've also tried to add an ACL for the specific IP for inside interface but with no results.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 13:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-remote-networks-via-gre-tunnels-between-cisco-routers/m-p/2349857#M344872</guid>
      <dc:creator>na26</dc:creator>
      <dc:date>2013-08-13T13:34:44Z</dc:date>
    </item>
  </channel>
</rss>

