<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5540 - unable to ping inside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048832#M418739</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Igor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have supplied the wrong config, it's unlikely to be a SVI config issue - rather than a basic routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the ASA know how to get back to the monitoring tools vlan?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside x.x.x.x y.y.y.y z.z.z.z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;x.x.x.x = monitoring tools vlan IP range&lt;/P&gt;&lt;P&gt;y.y.y.y = subnet mask&lt;/P&gt;&lt;P&gt;z.z.z.z = next hop layer 3 routing IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Oct 2008 10:21:25 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2008-10-10T10:21:25Z</dc:date>
    <item>
      <title>ASA 5540 - unable to ping inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048831#M418738</link>
      <description>&lt;P&gt;Hi all. We have recently upgraded from PIX to ASA5540 and we have seen a rather strange thing going on. In a nutshell we can ping the inside interface of the ASA from any network range on our 6500(which is connected directly behind the ASA on the inside) except one in which our monitoring tools are placed. On the inside interface there is an ACL that permits everything from our core networks but it doesn't help which is really strange.&lt;/P&gt;&lt;P&gt;In the ASDM I can see messages like this:&lt;/P&gt;&lt;P&gt;IDS:2004 ICMP echo request from x.x.x.x to y.y.y.y on interface inside. I don't think that this is the problem but I could be wrong.&lt;/P&gt;&lt;P&gt;Here is also the configuration of the VLAN interface for the VLAN from which we cannot ping the inside interface altough we can ping to and from that VLAN and the machines without problem. The only problem is pinging the inside interface of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlanx&lt;/P&gt;&lt;P&gt; ip address x.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt; ip directed-broadcast 199&lt;/P&gt;&lt;P&gt; ip accounting output-packets&lt;/P&gt;&lt;P&gt; ip pim sparse-dense-mode&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; load-interval 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did anyone encounter problem like this before? Thanks in advance for any help.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048831#M418738</guid>
      <dc:creator>IgorHamzic</dc:creator>
      <dc:date>2020-02-21T11:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - unable to ping inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048832#M418739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Igor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have supplied the wrong config, it's unlikely to be a SVI config issue - rather than a basic routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the ASA know how to get back to the monitoring tools vlan?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside x.x.x.x y.y.y.y z.z.z.z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;x.x.x.x = monitoring tools vlan IP range&lt;/P&gt;&lt;P&gt;y.y.y.y = subnet mask&lt;/P&gt;&lt;P&gt;z.z.z.z = next hop layer 3 routing IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2008 10:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048832#M418739</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-10T10:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - unable to ping inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048833#M418740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it can route back to that network because from ASA I can ping all the PC's, servers etc. in that network.&lt;/P&gt;&lt;P&gt;It was the first thing I checked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2008 10:32:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048833#M418740</guid>
      <dc:creator>IgorHamzic</dc:creator>
      <dc:date>2008-10-10T10:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - unable to ping inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048834#M418741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are not being consistant - you state above you can ping pc's and server in that network, but your initial post you state "In a nutshell we can ping the inside interface of the ASA from any network range on our 6500(which is connected directly behind the ASA on the inside) except one in which our monitoring tools are placed"  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which actually indicates the monitoring tools are in a seperate network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please clarify.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2008 10:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048834#M418741</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-10T10:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - unable to ping inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048835#M418744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's right. The monitoring tools are in a separate network. From the ASA we can ping every server,PC etc. in the core LAN no matter in what network they are in.&lt;/P&gt;&lt;P&gt;From the core LAN we can ping the inside interface of the ASA from all networks except from the network in which the monitoring tools are located which is weird because I can ping the monitoring servers from the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2008 10:51:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048835#M418744</guid>
      <dc:creator>IgorHamzic</dc:creator>
      <dc:date>2008-10-10T10:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - unable to ping inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048836#M418745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the output of the following on the ASA:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the output of your core layer routing device:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show ip route &amp;lt;&lt;IP subnet="" of="" monitoring=""&gt;&amp;gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2008 12:30:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048836#M418745</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-10T12:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - unable to ping inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048837#M418746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the problem. It really was in the routing. I found the problem in the routing table where one digit was off.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2008 12:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048837#M418746</guid>
      <dc:creator>IgorHamzic</dc:creator>
      <dc:date>2008-10-10T12:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5540 - unable to ping inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048838#M418747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2008 13:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048838#M418747</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-10T13:25:57Z</dc:date>
    </item>
    <item>
      <title>hello</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048839#M418748</link>
      <description>&lt;PRE class="tw-data-text vk_txt tw-ta tw-text-small" data-fulltext="" data-placeholder="Traducción" dir="ltr" id="tw-target-text" style="unicode-bidi: -webkit-isolate; border: none; padding: 0px 0.14em 0px 0px; position: relative; margin-bottom: 0px; resize: none; font-family: inherit; overflow: hidden; width: 237.5px; color: rgb(33, 33, 33); height: 144px; font-size: 16px !important; line-height: 24px !important; background-color: rgb(255, 255, 255);"&gt;
hello

I have the same problem, but do not understand how the route should be created in the core layer routing device .&lt;/PRE&gt;</description>
      <pubDate>Wed, 26 Nov 2014 15:09:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-unable-to-ping-inside-interface/m-p/1048839#M418748</guid>
      <dc:creator>negamartintap</dc:creator>
      <dc:date>2014-11-26T15:09:07Z</dc:date>
    </item>
  </channel>
</rss>

