<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Once again about pinging ASA's Outside interface from Internal network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497096#M660170</link>
    <description>&lt;P&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; sans-serif&amp;amp;quot: ; font-family: Arial; , &amp;amp;quot: ; Arial&amp;amp;quot: ; "&gt;Dear all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt;"&gt;&lt;SPAN style="font-family: Arial;"&gt;recently I faced a problem when we launched HP OV monitoring system. It is required to ping all enabled interfaces on ASA. "Inside" interface is monitored well but "Outside" is unavailable by ICMP and due to this alarm generated. I know that PIX's and ASA's with 7.x versions of software don't allow to do this (this is clearly noticed in documentation, &lt;/SPAN&gt;&lt;A href="https://community.cisco.com/" target="_blank"&gt;&lt;SPAN style="font-family: Arial;"&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-family: Arial;"&gt; for example). But in &lt;/SPAN&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/config.html" target="_blank"&gt;&lt;SPAN style="font-family: Arial;"&gt;documentation&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-family: Arial;"&gt; for version 8.2 (actually this version software installed now) I can't find any information regarding this question. I wonder if I missed something and such function was enabled in recent versions of software? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Cheers&lt;/SPAN&gt;,&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Dmitriy&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:21:24 GMT</pubDate>
    <dc:creator>Helpdesk_</dc:creator>
    <dc:date>2019-03-11T18:21:24Z</dc:date>
    <item>
      <title>Once again about pinging ASA's Outside interface from Internal network</title>
      <link>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497096#M660170</link>
      <description>&lt;P&gt;&lt;SPAN style=": ; color: #333333; font-size: 10pt; sans-serif&amp;amp;quot: ; font-family: Arial; , &amp;amp;quot: ; Arial&amp;amp;quot: ; "&gt;Dear all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt;"&gt;&lt;SPAN style="font-family: Arial;"&gt;recently I faced a problem when we launched HP OV monitoring system. It is required to ping all enabled interfaces on ASA. "Inside" interface is monitored well but "Outside" is unavailable by ICMP and due to this alarm generated. I know that PIX's and ASA's with 7.x versions of software don't allow to do this (this is clearly noticed in documentation, &lt;/SPAN&gt;&lt;A href="https://community.cisco.com/" target="_blank"&gt;&lt;SPAN style="font-family: Arial;"&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-family: Arial;"&gt; for example). But in &lt;/SPAN&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/config.html" target="_blank"&gt;&lt;SPAN style="font-family: Arial;"&gt;documentation&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-family: Arial;"&gt; for version 8.2 (actually this version software installed now) I can't find any information regarding this question. I wonder if I missed something and such function was enabled in recent versions of software? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Cheers&lt;/SPAN&gt;,&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Dmitriy&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:21:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497096#M660170</guid>
      <dc:creator>Helpdesk_</dc:creator>
      <dc:date>2019-03-11T18:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Once again about pinging ASA's Outside interface from Intern</title>
      <link>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497097#M660172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i think its still not possible but i can confirm on that, its more of a security feature which doesnt let u ping accross the asa and dont htin kthat would change&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in any case i can confirm tht&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 06:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497097#M660172</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T06:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Once again about pinging ASA's Outside interface from Intern</title>
      <link>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497098#M660174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look here, maybe you know it:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H2 class="pCRC_CmdRefCommand"&gt;management-access&lt;/H2&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/m_72.html#wp1794331"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/m_72.html#wp1794331&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the feedback?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 06:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497098#M660174</guid>
      <dc:creator>netsec</dc:creator>
      <dc:date>2010-08-05T06:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Once again about pinging ASA's Outside interface from Intern</title>
      <link>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497099#M660176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That’s is only to access the interface on the other side through the vpn tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The idea behind this is since you are using vpn to get in through the outside, there is no reason why I should be denying you from accessing the firewall using my inside ip because ideally vpn means internal (network that u trust) so they are like your inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This feature is mainly introduced to manage the firewall through the vpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command works only for the vpn traffic and also you can configure only 1 interface as management-access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 06:47:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497099#M660176</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T06:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Once again about pinging ASA's Outside interface from Intern</title>
      <link>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497100#M660183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN style="color: #000000; font-size: 10pt; "&gt;Dmitriy,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; "&gt;Jitendriya is correct--it is still not possible to ping a far-side interface on the ASA. This is by design and cannot be changed due to security restrictions. Here is the documentation for 8.2 that outlines this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i1.html#wp1697623"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i1.html#wp1697623&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;The adaptive security appliance only responds to ICMP traffic sent to the interface that traffic comes in on; you cannot send ICMP traffic through an interface to a far interface. &lt;/PRE&gt;&lt;BR /&gt; Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 18:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497100#M660183</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-08-05T18:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Once again about pinging ASA's Outside interface from Intern</title>
      <link>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497101#M660188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot to all of you, guys. I will keep in mind that this is not possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regrads,&lt;/P&gt;&lt;P&gt;Dmitriy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 09:30:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/once-again-about-pinging-asa-s-outside-interface-from-internal/m-p/1497101#M660188</guid>
      <dc:creator>Helpdesk_</dc:creator>
      <dc:date>2010-08-06T09:30:58Z</dc:date>
    </item>
  </channel>
</rss>

