<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot Ping ASA IP Addresses in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790708#M7407</link>
    <description>&lt;P&gt;you said you can ping when your PC is VLAN 1 (10.10.1.10) to the default gateway of the ASA.&lt;BR /&gt;if that correct than you have to understand you can not ping from PC in VLAN1 and you want to&lt;BR /&gt;ping to VLAN-X on ASA interface X. this is by default.&lt;BR /&gt;&lt;BR /&gt;if you try to ping the default gateway of ASA in its respective ip address range it will ping back/reply the pings&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jan 2019 20:53:51 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2019-01-29T20:53:51Z</dc:date>
    <item>
      <title>Cannot Ping ASA IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790680#M7403</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the following Network Setup:&lt;/P&gt;&lt;P&gt;ASA 5505(Security Plus License) --&amp;gt;Cisco Switch WS-C2960-8TC-L&amp;nbsp;--&amp;gt;PC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA has 8 interface VLANs, each one with an IP assigned. Cisco Switch has also 8 VLANS each one with an IP assigned.&lt;/P&gt;&lt;P&gt;My PC belongs to 10.10.1.0/24 network, and PC interface on SW is mode access VLAN 1. Link of ASA to Switch is trunk on both sides, allowing all VLANs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can successfully ping 10.10.2.2 (SW IP VLAN 2), but i cannot ping 10.10.2.1 (ASA IP VLAN 2).&lt;/P&gt;&lt;P&gt;In fact, i cannot ping any other FW IP except the one from Interface VLAN 1 (10.10.1.10).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All FW interfaces have the same security level (100), i have enabled same-security-traffic permit inter-interface, same-security-traffic permit intra-interface, inspect icmp and&amp;nbsp;icmp permit any USERS (VLAN 2).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please assist in order to resolve the issue? I have also attached the configuration from ASA and Switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Stef&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790680#M7403</guid>
      <dc:creator>Net_Stef</dc:creator>
      <dc:date>2020-02-21T16:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Ping ASA IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790685#M7405</link>
      <description>&lt;P&gt;looking into your config. your switch interface FastEthernet 0/8 trunk connected to ASA Ethernet0/1. your config looks ok can you make sure the cables are connected properly.&lt;/P&gt;&lt;P&gt;can you share share the output of the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show interface fastethernet 08&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;show interface ethernet0/1&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 20:24:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790685#M7405</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-29T20:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Ping ASA IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790700#M7406</link>
      <description>&lt;P&gt;Hello Sheraz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SW-1#show interfaces fastEthernet 0/8&lt;BR /&gt;FastEthernet0/8 is up, line protocol is up (connected)&lt;BR /&gt;Hardware is Fast Ethernet, address is 1c17.d308.9188 (bia 1c17.d308.9188)&lt;BR /&gt;Description: ASA5505&lt;BR /&gt;MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,&lt;BR /&gt;reliability 255/255, txload 1/255, rxload 1/255&lt;BR /&gt;Encapsulation ARPA, loopback not set&lt;BR /&gt;Keepalive set (10 sec)&lt;BR /&gt;Full-duplex, 100Mb/s, media type is 10/100BaseTX&lt;BR /&gt;input flow-control is off, output flow-control is unsupported&lt;BR /&gt;ARP type: ARPA, ARP Timeout 04:00:00&lt;BR /&gt;Last input 00:00:04, output 00:00:00, output hang never&lt;BR /&gt;Last clearing of "show interface" counters never&lt;BR /&gt;Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0&lt;BR /&gt;Queueing strategy: fifo&lt;BR /&gt;Output queue: 0/40 (size/max)&lt;BR /&gt;5 minute input rate 577000 bits/sec, 62 packets/sec&lt;BR /&gt;5 minute output rate 28000 bits/sec, 31 packets/sec&lt;BR /&gt;106245 packets input, 119098143 bytes, 0 no buffer&lt;BR /&gt;Received 142 broadcasts (108 multicasts)&lt;BR /&gt;1 runts, 0 giants, 0 throttles&lt;BR /&gt;1 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored&lt;BR /&gt;0 watchdog, 108 multicast, 0 pause input&lt;BR /&gt;0 input packets with dribble condition detected&lt;BR /&gt;64025 packets output, 6785852 bytes, 0 underruns&lt;BR /&gt;0 output errors, 0 collisions, 1 interface resets&lt;BR /&gt;0 babbles, 0 late collision, 0 deferred&lt;BR /&gt;0 lost carrier, 0 no carrier, 0 PAUSE output&lt;BR /&gt;0 output buffer failures, 0 output buffers swapped out&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW# sh int eth0/1&lt;BR /&gt;Interface Ethernet0/1 "", is up, line protocol is up&lt;BR /&gt;Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt;Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;BR /&gt;Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt;Description: SW-1&lt;BR /&gt;Available but not configured via nameif&lt;BR /&gt;MAC address 0081.c466.d58b, MTU not set&lt;BR /&gt;IP address unassigned&lt;BR /&gt;66961 packets input, 7268173 bytes, 0 no buffer&lt;BR /&gt;Received 1655 broadcasts, 0 runts, 0 giants&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;6782 switch ingress policy drops&lt;BR /&gt;110885 packets output, 123778937 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 rate limit drops&lt;BR /&gt;0 switch egress policy drops&lt;BR /&gt;0 input reset drops, 0 output reset drops&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 20:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790700#M7406</guid>
      <dc:creator>Net_Stef</dc:creator>
      <dc:date>2019-01-29T20:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Ping ASA IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790708#M7407</link>
      <description>&lt;P&gt;you said you can ping when your PC is VLAN 1 (10.10.1.10) to the default gateway of the ASA.&lt;BR /&gt;if that correct than you have to understand you can not ping from PC in VLAN1 and you want to&lt;BR /&gt;ping to VLAN-X on ASA interface X. this is by default.&lt;BR /&gt;&lt;BR /&gt;if you try to ping the default gateway of ASA in its respective ip address range it will ping back/reply the pings&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 20:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-asa-ip-addresses/m-p/3790708#M7407</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-29T20:53:51Z</dc:date>
    </item>
  </channel>
</rss>

