<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cant Ping Sub-Interfaces (ASA 5520) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cant-ping-sub-interfaces-asa-5520/m-p/534676#M425665</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently set up an Active/Standby failover configuration with 2 sub-interfaces configured on my g0/0 interface (g0/0.1 and g0/0.2) for some reason I cant ping either of these from my testing server (when the server is on the correct network and subnet to test the interface)? I am not sure whats going on... I included a print out of my current interface and failover configuration. The testing server is connected to a Dell 2724 switch and so is the interfaces in question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.1&lt;/P&gt;&lt;P&gt;vlan 10&lt;/P&gt;&lt;P&gt;nameif Outside1&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 66.38.x.x 255.255.x.x standby 66.38.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.2&lt;/P&gt;&lt;P&gt;vlan 20&lt;/P&gt;&lt;P&gt;nameif Outside2&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 64.187.x.x 255.255.x.x standby 64.187.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;nameif DMZ&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.10.x.x 255.255.x.x standby 10.10.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;nameif Private&lt;/P&gt;&lt;P&gt;security-level 40&lt;/P&gt;&lt;P&gt;ip address 192.168.x.x 255.255.x.x standby 192.168.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;description STATE Failover Interface&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.x.x 255.255.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Outside1 1500&lt;/P&gt;&lt;P&gt;mtu Outside2 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu Private 1500&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface FoInt GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link FoInt GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip FoInt 192.168.x.x 255.255.x.x standby 192.168.x.x&lt;/P&gt;&lt;P&gt;monitor-interface Outside1&lt;/P&gt;&lt;P&gt;monitor-interface Outside2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:58:23 GMT</pubDate>
    <dc:creator>chrisbicm</dc:creator>
    <dc:date>2020-02-21T08:58:23Z</dc:date>
    <item>
      <title>Cant Ping Sub-Interfaces (ASA 5520)</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-sub-interfaces-asa-5520/m-p/534676#M425665</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently set up an Active/Standby failover configuration with 2 sub-interfaces configured on my g0/0 interface (g0/0.1 and g0/0.2) for some reason I cant ping either of these from my testing server (when the server is on the correct network and subnet to test the interface)? I am not sure whats going on... I included a print out of my current interface and failover configuration. The testing server is connected to a Dell 2724 switch and so is the interfaces in question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.1&lt;/P&gt;&lt;P&gt;vlan 10&lt;/P&gt;&lt;P&gt;nameif Outside1&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 66.38.x.x 255.255.x.x standby 66.38.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.2&lt;/P&gt;&lt;P&gt;vlan 20&lt;/P&gt;&lt;P&gt;nameif Outside2&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 64.187.x.x 255.255.x.x standby 64.187.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;nameif DMZ&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.10.x.x 255.255.x.x standby 10.10.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;nameif Private&lt;/P&gt;&lt;P&gt;security-level 40&lt;/P&gt;&lt;P&gt;ip address 192.168.x.x 255.255.x.x standby 192.168.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;description STATE Failover Interface&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.x.x 255.255.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Outside1 1500&lt;/P&gt;&lt;P&gt;mtu Outside2 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu Private 1500&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface FoInt GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link FoInt GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip FoInt 192.168.x.x 255.255.x.x standby 192.168.x.x&lt;/P&gt;&lt;P&gt;monitor-interface Outside1&lt;/P&gt;&lt;P&gt;monitor-interface Outside2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-sub-interfaces-asa-5520/m-p/534676#M425665</guid>
      <dc:creator>chrisbicm</dc:creator>
      <dc:date>2020-02-21T08:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cant Ping Sub-Interfaces (ASA 5520)</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-sub-interfaces-asa-5520/m-p/534677#M425666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your sub-interface config is fine, except you probably need to assign different security level between them unless if you already planned for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally, it's on the switch-side that need to be configured accordingly. The trunk link between firewall and switch uses DOT1Q encapsulation (IEEE). I am not sure whether Dell support it. Make sure the trunk allows whatever Vlan you assigned to Firewall sub-interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a008054c515.html#wp1051819" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a008054c515.html#wp1051819&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be able to ping the interface, make sure you allow firewall to allow/permit icmp to hit the interface using 'icmp' command, e.g "icmp permit any Outside2"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, what's the gateway for your server? Is it ASA sub-interface (according to vlan) or VLAN IP on the switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/ps6120/products_command_reference_chapter09186a00805fba52.html#wp1615091" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/ps6120/products_command_reference_chapter09186a00805fba52.html#wp1615091&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that, you need to apply normal firewall ACL, static NAT and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jun 2006 13:36:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-sub-interfaces-asa-5520/m-p/534677#M425666</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-06-16T13:36:40Z</dc:date>
    </item>
  </channel>
</rss>

