10-25-2016 02:07 AM - edited 03-12-2019 01:26 AM
Hi all,
my architecture is :
and my ASA config is:
interface GigabitEthernet0
nameif outside
security-level 0
ip address 192.168.2.1 255.255.255.0
!
interface GigabitEthernet1
nameif inside
security-level 100
ip address 10.30.60.1 255.255.255.0
!
interface GigabitEthernet2
nameif dmz
security-level 50
ip address 10.30.61.1 255.255.255.0
!
ftp mode passive
object network inside-subnet
subnet 10.30.60.0 255.255.255.0
object network dmz-subnet
subnet 10.30.61.0 255.255.255.0
pager lines 24
mtu outside 1500
mtu inside 1500
mtu dmz 1500
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
!
object network inside-subnet
nat (inside,outside) dynamic interface
object network dmz-subnet
nat (dmz,outside) dynamic interface
but ping is not work from R3 (inside) to R2 (outside)
thanks in advance,
Regards,
MM
10-25-2016 04:12 AM
Check below things.
1) Do you have default route or return route towards ASA on both router?
2) Do you have command "same-security-traffic permit inter-interface" in ASA config if not you have to add that.
Kindly rate for useful post
10-26-2016 01:41 AM
Tahnks Pawan for your reply,
How i can adjust default route?
Regards,
MM
10-26-2016 01:50 AM
give me the output sh ip route from both router
11-02-2016 03:05 AM
R3#sh ip route
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route
Gateway of last resort is not set
C 10.30.60.0 is directly connected, FastEthernet0/0
R2#sh ip route
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route
Gateway of last resort is not set
C 192.168.2.0/24 is directly connected, FastEthernet0/0
Thanks Pawan,
Ragards,
MM
11-02-2016 03:11 AM
You do not have route to reach each other please add below route.
on R1
ip route 192.168.2.0 2 255.255.255.0 10.30.60.1
and on R2
ip route 10.30.60.0 255.255.255.0 192.168.2.1
11-02-2016 03:26 AM
I tried that but don't working
R3#ping 192.168.2.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
11-02-2016 03:55 AM
can you give me a basic firewall configuration?
Thanks Pawan,
Regards,
MM
11-02-2016 04:07 AM
Do you have command "same-security-traffic permit inter-interface" in ASA config if not you have to add that
10-26-2016 11:47 PM
Default route :
do check the route below on ASA
#route outside 0 0 192.168.2.2
also do check the global service policy inspection
#policy-map global_policy
#inspect icmp
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: