<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't Ping ASA different interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945965#M435945</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jong,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yep, that is right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a good one!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 May 2012 23:38:39 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-05-25T23:38:39Z</dc:date>
    <item>
      <title>Can't Ping ASA different interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945960#M435932</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We are using Cisco ASA 5580 (8.2) firewall. When i try to ping from inside lan to firewall DMZ interface IP it is not pingable and but from inside users i am able to ping firewall inside interface IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think we can't ping to other interfaces of ASA by default. But can we allow the single IP address who can ping all the interfaces of firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are not doing any natting in firewall, for that we used the Load Balancer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945960#M435932</guid>
      <dc:creator>Jayesh Rajan</dc:creator>
      <dc:date>2019-03-11T23:11:13Z</dc:date>
    </item>
    <item>
      <title>Can't Ping ASA different interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945961#M435933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jayesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA as a security device will not allow you to ping&amp;nbsp; a distant interface....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is a distant interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an example imagine you are on a host behind the inside interface.. You will be able to ping the inside interface but you wil NOT be able to ping the DMZ or outside interface... This because they are distant interface for the inside host..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is nothing you can do to change that behavior, this is done as a security meassure by the ASA ( Built-in feature)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Do rate all the helpful posts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 17:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945961#M435933</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-05-24T17:48:33Z</dc:date>
    </item>
    <item>
      <title>Can't Ping ASA different interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945962#M435935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jayesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio is right that pingis not allowed by default. But you can still allow the PING by allowing ICMP in your access-list DMZ for specific host. You need also to allow ICMP from DMZ inteface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# icmp permit host xxxx echo DMZ&lt;/P&gt;&lt;P&gt;ASA(config)# access-list DMZ-In extended permit icmp xxxx(DMZ host) host yyyy(inside host)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿Thanks,&lt;/P&gt;&lt;P&gt;Jong&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 17:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945962#M435935</guid>
      <dc:creator>jong_r0602</dc:creator>
      <dc:date>2012-05-25T17:13:28Z</dc:date>
    </item>
    <item>
      <title>Can't Ping ASA different interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945963#M435936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jong,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think he is refering to ping the DMZ interface from the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 21:10:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945963#M435936</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-05-25T21:10:13Z</dc:date>
    </item>
    <item>
      <title>Can't Ping ASA different interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945964#M435944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oh yes.. its the interface and not the host. Your correct, ping is not allowed for this scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jong&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 21:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945964#M435944</guid>
      <dc:creator>jong_r0602</dc:creator>
      <dc:date>2012-05-25T21:22:11Z</dc:date>
    </item>
    <item>
      <title>Can't Ping ASA different interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945965#M435945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jong,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yep, that is right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a good one!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 23:38:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945965#M435945</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-05-25T23:38:39Z</dc:date>
    </item>
    <item>
      <title>Can't Ping ASA different interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945966#M435946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks All....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any cisco document is available where this mentioned?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2012 06:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945966#M435946</guid>
      <dc:creator>Jayesh Rajan</dc:creator>
      <dc:date>2012-06-10T06:30:26Z</dc:date>
    </item>
    <item>
      <title>Can't Ping ASA different interfaces</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945967#M435947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes. Pls refer the below cisco document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2012 09:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-asa-different-interfaces/m-p/1945967#M435947</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-06-10T09:36:54Z</dc:date>
    </item>
  </channel>
</rss>

