<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't ping ASA 5510 inside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202892#M358272</link>
    <description>&lt;P&gt; &lt;SPAN style="font-size: 12pt;"&gt;Hello, everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;I&amp;nbsp; ran into a very strange icmp ping issue that I could not seem to undersatand, hope someone can provide a troubleshooting tip on this. The network has been working fine other than the issue listed below, L2L VPN works&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;fine and all three data centers can access each other via L2L VPN.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;I have three ASA5510:&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; asa10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Location: datacenter10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside IP: 10.10.10.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L2LVPN:&amp;nbsp; asa10TOasa20, asa10TOasa30&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; asa20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Location: datacenter20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside IP: 10.20.20.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L2LVPN:&amp;nbsp; asa10TOasa20, asa10TOasa30&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; asa30&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Location: datacenter30&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside IP: 10.30.30.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L2LVPN:&amp;nbsp; asa10TOasa20, asa10TOasa30&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Other than, global IP addresses, subnet IP addresses, the run configs are pretty much the same.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Problems:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;From network 10.10.10.0, can ping 10.10.10.254, 10.20.20.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can't ping 10.30.30.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;From network 10.20.20.0, can ping 10.10.10.254, 10.20.20.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can't ping 10.30.30.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;From network 10.30.30.0, can ping 10.20.20.254, 10.30.30.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can't ping 10.10.10.254, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Please help by providing your insights or troubleshooting tips. My customer would not allow me to post configs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:28:00 GMT</pubDate>
    <dc:creator>bc4switch</dc:creator>
    <dc:date>2019-03-12T01:28:00Z</dc:date>
    <item>
      <title>Can't ping ASA 5510 inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202892#M358272</link>
      <description>&lt;P&gt; &lt;SPAN style="font-size: 12pt;"&gt;Hello, everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;I&amp;nbsp; ran into a very strange icmp ping issue that I could not seem to undersatand, hope someone can provide a troubleshooting tip on this. The network has been working fine other than the issue listed below, L2L VPN works&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;fine and all three data centers can access each other via L2L VPN.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;I have three ASA5510:&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; asa10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Location: datacenter10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside IP: 10.10.10.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L2LVPN:&amp;nbsp; asa10TOasa20, asa10TOasa30&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; asa20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Location: datacenter20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside IP: 10.20.20.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L2LVPN:&amp;nbsp; asa10TOasa20, asa10TOasa30&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; asa30&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Location: datacenter30&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside IP: 10.30.30.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L2LVPN:&amp;nbsp; asa10TOasa20, asa10TOasa30&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Other than, global IP addresses, subnet IP addresses, the run configs are pretty much the same.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Problems:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;From network 10.10.10.0, can ping 10.10.10.254, 10.20.20.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can't ping 10.30.30.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;From network 10.20.20.0, can ping 10.10.10.254, 10.20.20.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can't ping 10.30.30.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;From network 10.30.30.0, can ping 10.20.20.254, 10.30.30.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can't ping 10.10.10.254, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Please help by providing your insights or troubleshooting tips. My customer would not allow me to post configs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202892#M358272</guid>
      <dc:creator>bc4switch</dc:creator>
      <dc:date>2019-03-12T01:28:00Z</dc:date>
    </item>
    <item>
      <title>Can't ping ASA 5510 inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202893#M358273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have spent hours trying to resolve it first time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case the issue was with dynamic nat. &lt;SPAN style="font-size: 10pt;"&gt;When you use object definition for PAT, please use range (excluding ip of the firewall) as opposed to subnet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Let me know if that helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Paul Preston &lt;BR /&gt;Proxar IT Ltd. Registered in England and Wales: 6744401- VAT: 942985479 &lt;BR /&gt;Tubs Hill House, London Road, Sevenoaks, Kent, TN13 1BL &lt;BR /&gt;Tel:&amp;nbsp; (+44) 0844 809 4335 &lt;BR /&gt;Fax: (+44) 01732 468 574 &lt;BR /&gt;Mob: (+44) 077 9509 3450 &lt;BR /&gt;Web: &lt;A href="https://community.cisco.com/www.proxar.co.uk" target="_blank"&gt;www.proxar.co.uk&lt;/A&gt; &lt;BR /&gt;&lt;SPAN&gt;Email: &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:paul.preston@proxar.co.uk"&gt;paul.preston@proxar.co.uk&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 14:22:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202893#M358273</guid>
      <dc:creator>Paul Preston</dc:creator>
      <dc:date>2013-04-14T14:22:32Z</dc:date>
    </item>
    <item>
      <title>Can't ping ASA 5510 inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202894#M358274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add the route-lookup to the nat statement,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;without configs we are blind&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 16:41:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202894#M358274</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-14T16:41:24Z</dc:date>
    </item>
    <item>
      <title>Re:Can't ping ASA 5510 inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202895#M358275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming that u have the vpn config in place, pls ensure that you have the following configured in the config mode on asa30&lt;BR /&gt;&lt;BR /&gt;man inside&lt;BR /&gt;&lt;BR /&gt;Where "inside" is the name of the interface u r trying to ping.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Apr 2013 17:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202895#M358275</guid>
      <dc:creator>Simerjeet Singh</dc:creator>
      <dc:date>2013-04-14T17:14:11Z</dc:date>
    </item>
    <item>
      <title>Re:Can't ping ASA 5510 inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202896#M358276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. "man inside" did work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But do you have to do this for L2L VPN? I mean is "man inside" a required configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 00:43:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202896#M358276</guid>
      <dc:creator>bc4switch</dc:creator>
      <dc:date>2013-04-15T00:43:19Z</dc:date>
    </item>
    <item>
      <title>Re:Can't ping ASA 5510 inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202897#M358277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bin, it is only required if u have management traffic directed towards interface over the vpn tunnel.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Sim.&lt;BR /&gt;&lt;BR /&gt;Please mark resolved questions as "Answered"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 02:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-5510-inside-interface/m-p/2202897#M358277</guid>
      <dc:creator>Simerjeet Singh</dc:creator>
      <dc:date>2013-04-15T02:34:59Z</dc:date>
    </item>
  </channel>
</rss>

