<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cant ping dmz interface ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989515#M439581</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ibrahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes the router ID of the ASA will be its highest IP address, but if you take a close look to the debugs and the packets that the ASA sends when it sees the WCCP server (Here I am, I see you); the IP address that the ASA uses to send the "I see you" message is the IP address of the closest interface to WCCP server. The highest IP adddress is only used to establish the GRE tunnel and perform the traffic redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Jul 2012 16:35:28 GMT</pubDate>
    <dc:creator>Luis Silva Benavides</dc:creator>
    <dc:date>2012-07-13T16:35:28Z</dc:date>
    <item>
      <title>cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989508#M439574</link>
      <description>&lt;P&gt;i just wanna make it clear, &lt;/P&gt;&lt;P&gt;can i ping asa interface that not in the same zone, for example im in inside zone, i can ping&amp;nbsp; asa inside interface, but i can i ping other asa interface(outside,dmz,etc) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just a newbie&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989508#M439574</guid>
      <dc:creator>superlubis</dc:creator>
      <dc:date>2019-03-11T23:29:59Z</dc:date>
    </item>
    <item>
      <title>cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989509#M439575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot ping the other interface ip's of the firewall...&amp;nbsp; that is a restricted by design..... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 06:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989509#M439575</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-12T06:01:18Z</dc:date>
    </item>
    <item>
      <title>cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989510#M439576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, you can't.&lt;/P&gt;&lt;P&gt;It is by design that you can't ping cross interfaces, ie: from inside host you can only ping the inside interface, and you can't ping dmz interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if you VPN in, you can ping 1 cross interface when you have the command: "management-access &lt;INTERFACENAME&gt;" configured.&lt;/INTERFACENAME&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 06:01:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989510#M439576</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-07-12T06:01:24Z</dc:date>
    </item>
    <item>
      <title>cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989511#M439577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot ping the distant interfaces of the firewalls from other zones.... Because the DMZ interface is not considered as the host in network... it is an firewall interface which is offering service for the dmz zone.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 06:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989511#M439577</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-12T06:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989512#M439578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No you Can't Ping the other interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But If you are connected via VPN in that case by using management access on your firewall you can ping the interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 06:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989512#M439578</guid>
      <dc:creator>gouravbathla</dc:creator>
      <dc:date>2012-07-12T06:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989513#M439579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adding to what gaurav said, you can use "management-access dmz"&amp;nbsp; command to manage the dmz interface via vpn. using this command you will be able to ping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use this command only for 1 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dinkar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 21:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989513#M439579</guid>
      <dc:creator>Dinkar Sharma</dc:creator>
      <dc:date>2012-07-12T21:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989514#M439580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And then my question came to,in my understanding in wccp router id is the highest ip address of interface. If wccp server in the diffrent zone as the router id then wccp must be have route to that interface. Whats the meaning "have route" ? For sure we cannot ping that highest ip if in diffrent zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 13:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989514#M439580</guid>
      <dc:creator>superlubis</dc:creator>
      <dc:date>2012-07-13T13:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989515#M439581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ibrahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes the router ID of the ASA will be its highest IP address, but if you take a close look to the debugs and the packets that the ASA sends when it sees the WCCP server (Here I am, I see you); the IP address that the ASA uses to send the "I see you" message is the IP address of the closest interface to WCCP server. The highest IP adddress is only used to establish the GRE tunnel and perform the traffic redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2012 16:35:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989515#M439581</guid>
      <dc:creator>Luis Silva Benavides</dc:creator>
      <dc:date>2012-07-13T16:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989516#M439582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;one question, which ip i should give NAT/ IP Public ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Jul 2012 04:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989516#M439582</guid>
      <dc:creator>superlubis</dc:creator>
      <dc:date>2012-07-14T04:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping dmz interface ?</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989517#M439583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ibrahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No need for nat as WCCP will work just for users behind the same ASA interface, so there is no need to use nat as the traffic will not go to a different zone or the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Jul 2012 05:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-dmz-interface/m-p/1989517#M439583</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-07-14T05:42:52Z</dc:date>
    </item>
  </channel>
</rss>

