cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
293
Views
0
Helpful
1
Replies

ASA Firewall Interface Ping

QUARK TARO
Level 3
Level 3

I have setup ASA 5525 firewall with inside, outside and DMZ.

From inside PC, I can ping the inside interface of the firewall, from DMZ system I can ping the DMZ interface of the firewall.

But from inside PC, I can not ping the DMZ interface, also from DMZ PC, I can not ping the inside interface of the firewall.

I have disabled anti-spoofing, ICMP is full allowed with icmp inspection. What else do I need to allow?

1 Reply 1

Marius Gunnerud
VIP Alumni
VIP Alumni

This is by design.  You will never be able to ping an ASA interface that is not the ingress interface.  There is no way around this.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card