<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cant ping within the DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849595#M956983</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hopefully this will help - i did a debug arp on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;arp-in: request at DMZ1 from 10.10.5.7 0006.5b3c.8901 for 10.10.5.6 0000.0000.00&lt;/P&gt;&lt;P&gt;00&lt;/P&gt;&lt;P&gt;arp-in: rqst for me from 10.10.5.7 for 10.10.5.6, on DMZ1&lt;/P&gt;&lt;P&gt;arp-set: added arp DMZ1 10.10.5.7 0006.5b3c.8901 and updating NPs at -772732892&lt;/P&gt;&lt;P&gt;arp-in: generating reply from 10.10.5.6 0005.5d18.fffb to 10.10.5.7 0006.5b3c.89&lt;/P&gt;&lt;P&gt;01&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Jan 2008 04:08:11 GMT</pubDate>
    <dc:creator>jerry.mcrae</dc:creator>
    <dc:date>2008-01-18T04:08:11Z</dc:date>
    <item>
      <title>cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849589#M956968</link>
      <description>&lt;P&gt;i have a DMZ with a www server and a ftp server - i cant ping between the two. if i issue a ping i get one reply then 3 failures - if i wait about three minutes i can issue the ping again get one reply the the rest fail. i can ping the switch from the servers and i can ping from the switch to the servers. i have also tried to browse from one server to the other by \\10.10.5.x\c$ and i get "no network provider accepted the given network path".&lt;/P&gt;&lt;P&gt;i can access the inside network and outside network no problem. i have connected the two servers via a crossover and the ping worked great.&lt;/P&gt;&lt;P&gt;im stumped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849589#M956968</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2019-03-11T11:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849590#M956973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jerry,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't tell you what the problem is because I'm not seeing it but... if you ping from one server to the other, do you see the traffic going through the firewall? You shouldn't be seeing this because both servers are on the same network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you are not seeing this, it means that the problem is not the firewall. If you are seeing the traffic then I would advise you to review your subnets because this should not be happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post here when you find a solution to your problem. I'm curious :).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Paulo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2008 10:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849590#M956973</guid>
      <dc:creator>pjhenriqs</dc:creator>
      <dc:date>2008-01-16T10:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849591#M956975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how can i check to see if the traffic is hitting the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2008 16:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849591#M956975</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2008-01-16T16:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849592#M956978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two ways. Either you check the logs or you configure a packet capture on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To check the logs, go into ASDM, under the Monitoring tab and click on Logging. Choose Debugging just to make sure you see everything. You should be able to filter the output by IP address/string.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To configure a capture, in the CLI do:&lt;/P&gt;&lt;P&gt;capture &lt;NAME-OF-CAPTURE&gt; interface &lt;INTERFACE-NAME&gt;&lt;/INTERFACE-NAME&gt;&lt;/NAME-OF-CAPTURE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then do show capture &lt;NAME-OF-CAPTURE&gt;&lt;/NAME-OF-CAPTURE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are more twists to this, but that should be enough for you to see if the traffic is going to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Paulo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2008 16:48:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849592#M956978</guid>
      <dc:creator>pjhenriqs</dc:creator>
      <dc:date>2008-01-16T16:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849593#M956980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i ran a logging buffered debug on the PIX - i am ping from 10.10.5.7 to 10.10.5.6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 17 2008 19:22:05 : %PIX-6-609001: Built local-host inside:10.10.5.6&lt;/P&gt;&lt;P&gt;Jan 17 2008 19:22:05 : %PIX-6-302020: Built ICMP connection for faddr 10.10.5.7/&lt;/P&gt;&lt;P&gt;512 gaddr 10.10.5.6/0 laddr 10.10.5.6/0&lt;/P&gt;&lt;P&gt;Jan 17 2008 19:22:05 : %PIX-6-110001: No route to 10.10.5.6 from 10.10.5.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 17 2008 19:22:08 : %PIX-6-302021: Teardown ICMP connection for faddr 10.10.5&lt;/P&gt;&lt;P&gt;.7/512 gaddr 10.10.5.6/0 laddr 10.10.5.6/0&lt;/P&gt;&lt;P&gt;Jan 17 2008 19:22:08 : %PIX-6-609002: Teardown local-host inside:10.10.5.6 durat&lt;/P&gt;&lt;P&gt;ion 0:00:02&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from a debug icmp trace i get this - on the same pix. i didnt get the replys on the 10.10.5.7 server but this says i did.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ICMP echo reply (len 32 id 512 seq 22785) 10.10.5.6 &amp;gt; 10.10.5.7&lt;/P&gt;&lt;P&gt;ICMP echo reply (len 32 id 512 seq 23041) 10.10.5.6 &amp;gt; 10.10.5.7&lt;/P&gt;&lt;P&gt;ICMP echo reply (len 32 id 512 seq 23297) 10.10.5.6 &amp;gt; 10.10.5.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could this be related to NAT?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 02:39:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849593#M956980</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2008-01-18T02:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849594#M956982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here is a copy of the PIX running config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 02:47:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849594#M956982</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2008-01-18T02:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849595#M956983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hopefully this will help - i did a debug arp on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;arp-in: request at DMZ1 from 10.10.5.7 0006.5b3c.8901 for 10.10.5.6 0000.0000.00&lt;/P&gt;&lt;P&gt;00&lt;/P&gt;&lt;P&gt;arp-in: rqst for me from 10.10.5.7 for 10.10.5.6, on DMZ1&lt;/P&gt;&lt;P&gt;arp-set: added arp DMZ1 10.10.5.7 0006.5b3c.8901 and updating NPs at -772732892&lt;/P&gt;&lt;P&gt;arp-in: generating reply from 10.10.5.6 0005.5d18.fffb to 10.10.5.7 0006.5b3c.89&lt;/P&gt;&lt;P&gt;01&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 04:08:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849595#M956983</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2008-01-18T04:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849596#M956985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jerry,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is definitely not a problem with the firewall. These two IP addresses are both on the same subnet so the traffic should not be going through the firewall!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check your switch/VLAN configuration and review why the traffic is going to the firewall and not directly to the host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Paulo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 09:11:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849596#M956985</guid>
      <dc:creator>pjhenriqs</dc:creator>
      <dc:date>2008-01-18T09:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849597#M956986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i plan to do a write erase on that switch Monday night. i attached the switch config.&lt;/P&gt;&lt;P&gt;i just ran this on the dmz switch.&lt;/P&gt;&lt;P&gt;the first ping is my laptop to dmz switch - the second is one on the servers in the dmz to the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOC-DMZ1-2950# debug ip icmp&lt;/P&gt;&lt;P&gt;ICMP packet debugging is on&lt;/P&gt;&lt;P&gt;NOC-DMZ1-2950#term mon&lt;/P&gt;&lt;P&gt;NOC-DMZ1-2950#undebug all&lt;/P&gt;&lt;P&gt;000302: *May 31 00:15:38.966: ICMP: echo reply sent, src 10.10.5.5, dst 172.16.1&lt;/P&gt;&lt;P&gt;.64&lt;/P&gt;&lt;P&gt;000303: *May 31 00:15:39.966: ICMP: echo reply sent, src 10.10.5.5, dst 172.16.1&lt;/P&gt;&lt;P&gt;.64&lt;/P&gt;&lt;P&gt;000304: *May 31 00:15:40.966: ICMP: echo reply sent, src 10.10.5.5, dst 172.16.1&lt;/P&gt;&lt;P&gt;.64&lt;/P&gt;&lt;P&gt;000305: *May 31 00:15:41.966: ICMP: echo reply sent, src 10.10.5.5, dst 172.16.1&lt;/P&gt;&lt;P&gt;.64&lt;/P&gt;&lt;P&gt;All possible debugging has been turned off&lt;/P&gt;&lt;P&gt;NOC-DMZ1-2950#term mon&lt;/P&gt;&lt;P&gt;NOC-DMZ1-2950# debug ip icmp&lt;/P&gt;&lt;P&gt;ICMP packet debugging is on&lt;/P&gt;&lt;P&gt;NOC-DMZ1-2950#&lt;/P&gt;&lt;P&gt;000306: *May 31 00:17:28.494: ICMP: echo reply sent, src 10.10.5.5, dst 10.10.5.&lt;/P&gt;&lt;P&gt;7&lt;/P&gt;&lt;P&gt;000307: *May 31 00:17:29.494: ICMP: echo reply sent, src 10.10.5.5, dst 10.10.5.&lt;/P&gt;&lt;P&gt;7&lt;/P&gt;&lt;P&gt;000308: *May 31 00:17:30.494: ICMP: echo reply sent, src 10.10.5.5, dst 10.10.5.&lt;/P&gt;&lt;P&gt;7&lt;/P&gt;&lt;P&gt;NOC-DMZ1-2950#undebug all&lt;/P&gt;&lt;P&gt;All possible debugging has been turned off&lt;/P&gt;&lt;P&gt;NOC-DMZ1-2950#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 16:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849597#M956986</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2008-01-18T16:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849598#M956989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i got the two servers to ping each other by entering static arp entrys in each of the dmz servers. &lt;/P&gt;&lt;P&gt;does this mean the switch isnt procesing the arp request properly? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2008 00:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849598#M956989</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2008-01-22T00:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849599#M956991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if i look at the arp table on one of the servers it shows all other servers have the dmz interface MAC as there MAC also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2008 01:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849599#M956991</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2008-01-22T01:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: cant ping within the DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849600#M956992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i had to disable proxy arp on the DMZ interface to make it work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX(config)# sysopt noproxyarp DMZ1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for every ones input to help resolve this issue!!!!!!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2008 01:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-ping-within-the-dmz/m-p/849600#M956992</guid>
      <dc:creator>jerry.mcrae</dc:creator>
      <dc:date>2008-01-22T01:43:03Z</dc:date>
    </item>
  </channel>
</rss>

