<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA cannot ping locally connected HSRP IP address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811579#M6692</link>
    <description>&lt;P&gt;my thoughts are when the power outrage happen and power restored the ASA come up online have change their role. by mean saying is asa read it flash memory/config and where ever was configured as primary or standby the role was chosen for these boxes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Feb 2019 10:10:19 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2019-02-28T10:10:19Z</dc:date>
    <item>
      <title>ASA cannot ping locally connected HSRP IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811559#M6691</link>
      <description>&lt;P&gt;Following a recent power outage at a remote site we lost the ability to manage the asa pair through the mgmt vlan 100.&lt;/P&gt;&lt;P&gt;The setup at the site is an active/standby asa pair, connected to 2 x core switches via the mgmt vlan100.&lt;/P&gt;&lt;P&gt;Vlan100 terminates on the core switches with the respective SVI's, 172.16.100.252 &amp;amp; 172.16.100.253.&lt;/P&gt;&lt;P&gt;The cores are running hsrp and the vlan 100 virtual ip is 172.16.100.254.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The static route on the asa used for management was&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;S 172.16.2.0 255.255.255.192 [1/0] via 172.25.86.254, MANAGEMENT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the outage, from either asa it is possible to ping both svi's .252 &amp;amp; .253, but not the virtual IP 172.16.100.254&lt;/P&gt;&lt;P&gt;Therefore as a workaround we changed the static route to&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;S 172.16.2.0 255.255.255.192 [1/0] via 172.25.86.253, MANAGEMENT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;and management was restored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am trying to understand is why we can no longer ping the virtual hsrp ip address 172.25.86.254 directly from the asa. We have other devices on this vlan (i.e. firepower firewalls) and we can ping&amp;nbsp; 172.25.86.254 from these devices, but not the asa's.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have cleared the arp cache on the core switches and the asa's and we have since failed back the asa's but it still isnt possible to ping the hsrp ip&amp;nbsp; 172.25.86.254&amp;nbsp; from the asa's.&lt;/P&gt;&lt;P&gt;I&lt;/P&gt;&lt;P&gt;f I run a debug ip icmp on either core switch I do not see any incoming packets when i issue the 'ping&amp;nbsp;172.16.100.254' from either asa.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please offer any thoughts?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811559#M6691</guid>
      <dc:creator>mrshabbs</dc:creator>
      <dc:date>2020-02-21T16:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA cannot ping locally connected HSRP IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811579#M6692</link>
      <description>&lt;P&gt;my thoughts are when the power outrage happen and power restored the ASA come up online have change their role. by mean saying is asa read it flash memory/config and where ever was configured as primary or standby the role was chosen for these boxes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 10:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811579#M6692</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-02-28T10:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA cannot ping locally connected HSRP IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811615#M6693</link>
      <description>Thanks but this doesn't explain why i cant ping a locally connected address - from either asa i can ping other addresses on the same subnet.</description>
      <pubDate>Thu, 28 Feb 2019 10:51:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811615#M6693</guid>
      <dc:creator>mrshabbs</dc:creator>
      <dc:date>2019-02-28T10:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA cannot ping locally connected HSRP IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811708#M6694</link>
      <description>&lt;P&gt;I'm wondering if something is going on with the sysopt noproxyarp:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s17.html#pgfId-1572088" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s17.html#pgfId-1572088&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It may have been in place but not saved before the outage.&lt;/P&gt;
&lt;P&gt;I would capture the traffic from the ASA when trying the ping filtering on the HSRP virtual address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 13:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3811708#M6694</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-02-28T13:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA cannot ping locally connected HSRP IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3812342#M6695</link>
      <description>&lt;P&gt;Hi Marvin&lt;/P&gt;&lt;P&gt;I have disabled proxyarp on the mgmt interface, this has made no difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran a capture on the arp traffic on the asa, if I am interpreting the output correctly then no response is being received?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;432: 07:26:39.422738 00c8.8b16.da73 ffff.ffff.ffff 0x0806 Length: 42&lt;BR /&gt;arp who-has 172.25.100.254 tell 172.25.100.8&lt;BR /&gt;433: 07:26:44.422738 00c8.8b16.da73 ffff.ffff.ffff 0x0806 Length: 42&lt;BR /&gt;arp who-has 172.25.100.254 tell 172.25.100.8&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have run a debug arp on the core switch but I cannot see any arp requests?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 08:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3812342#M6695</guid>
      <dc:creator>mrshabbs</dc:creator>
      <dc:date>2019-03-01T08:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA cannot ping locally connected HSRP IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3812445#M6696</link>
      <description>&lt;P&gt;Can you give us a more complete network picture?&lt;/P&gt;
&lt;P&gt;You mention 172.25.100.254 is what you are trying to reach. Your ASA's source address is 172.25.100.8 per the output your shared.&lt;/P&gt;
&lt;P&gt;However in your first post you mentioned 172.25.86.254 as a gateway in your static route. How does that relate to the 172.25.100.x subnet?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 11:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-ping-locally-connected-hsrp-ip-address/m-p/3812445#M6696</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-03-01T11:22:13Z</dc:date>
    </item>
  </channel>
</rss>

