cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2886
Views
1
Helpful
6
Replies

ASA 5505 Dual WAN - Ping inactive wan from outside?

Dustin Barnett
Level 1
Level 1

I currently have some small branch offices using ASA 5505 with Security Plus license and dual wan connections. They are configured wil an sla monitor so if the primary WAN goes down the secondary connection becomes active. This works as expected, however...

I can't ping the non-active interface from an outside source. I beleive this is by design or due to some limitation on the 5505. The problem is that I don't know if the backup WAN connection is functioning normally without forcing the ASA to make it active. We use a flaky wireless connection for the backups. The problem recently bit me because both WAN connections were offline.

I'm looking for an easy way to monitor the inactive wan interface, preferably by pinging from an outside location. Is this possible?

1 Accepted Solution

Accepted Solutions

lcambron
Level 3
Level 3

Hello,

This wont work because the ASA receives the ping on the backup link but has the default route pointing to the outside.

You would have to add a more spefic route for your IP.

Example:

If you want to ping coming from IP 1.1.1.1

route outside 0 0 x.x.1.1 1 track 1

route backup 0 0 x.x.2.2 250

route backup 1.1.1.1 255.255.255.255 x.x.2.2

Regards,

Felipe.

Remember to rate useful posts.

View solution in original post

6 Replies 6

Dustin Barnett
Level 1
Level 1

No activity... Is there a better area to post this question?

Thanks, this is exactly what I needed! I didn't realize it was a routing issue.

lcambron
Level 3
Level 3

Hello,

This wont work because the ASA receives the ping on the backup link but has the default route pointing to the outside.

You would have to add a more spefic route for your IP.

Example:

If you want to ping coming from IP 1.1.1.1

route outside 0 0 x.x.1.1 1 track 1

route backup 0 0 x.x.2.2 250

route backup 1.1.1.1 255.255.255.255 x.x.2.2

Regards,

Felipe.

Remember to rate useful posts.

Hello,
is it possible to make it ping reachable to both interface. ? when we change route , other interface not alternatly can not ping.
Thanks

Hi!

 

I'm having the same problem with my network. Please, give me a light here.

 

I have dual ISP and I want to monitor my backup interface, that has the ip address of 192.168.1.0.

 

My routes are like this

 

NET 0 0 192.168.0.1 1 track 1

VIVO 0 0 192.168.1.1 254

 

my inside network is 192.168.50.0

 

I want to monitor the backup interface while it's in standby, is it possible?

 

I've tryied to apply some routing configurations, but without success.

 

Could someone here help me with this?

Thanks

lcambron
Level 3
Level 3

Hello,

Also be aware of CSCsy89178, telnet and ssh work to the backup but icmp doesnt.

Regards,

Felipe.

Remember to rate useful posts.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card