cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7203
Views
0
Helpful
2
Replies

FTD can't ping interface IP address

Support ACME
Level 1
Level 1

Dear ALL,

 

I'm configuring the FTD firewall as internal firewall, I have two interfaces for inside and outside network, the inside interface IP address is 192.168.100.1/24 and the outside network is 172.16.30.1/24.

I have allow all traffic in access control policy, now I can use the inside network 192.168.100.2 to ping 172.16.30.2, but i can't ping to 172.16.30.1( the interface IP), then from 172.16.30.2 ping to 192.168.100.2 is success, but ping to 192.168.100.1 are failed.

Anyone can  help?

 

 

TungHo

1 Accepted Solution

Accepted Solutions

GRANT3779
Spotlight
Spotlight
Just so I understand, are you saying you can ping through the firewall from devices going in to out and vice versa? but unable to ping the actual firewall interface ip addresses?
Are you trying to ping the Outside interface IP from a device on the inside? Also, ping the inside interface ip from a device on the Outside?
On the ASA you cannot do this by design and it may be the same for FTD. I don't think you send icmp traffic via one interface, destined for another physical interface on the same device.

View solution in original post

2 Replies 2

GRANT3779
Spotlight
Spotlight
Just so I understand, are you saying you can ping through the firewall from devices going in to out and vice versa? but unable to ping the actual firewall interface ip addresses?
Are you trying to ping the Outside interface IP from a device on the inside? Also, ping the inside interface ip from a device on the Outside?
On the ASA you cannot do this by design and it may be the same for FTD. I don't think you send icmp traffic via one interface, destined for another physical interface on the same device.

Dear GRANT3779,

 

thanks for your clarification.

 

TungHo

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: