cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
359
Views
0
Helpful
1
Replies

ASA Interface Question

drbabbers
Level 3
Level 3

All,

Why is it on an ASA that I can't source ping from an interface to another interface directly connected to the ASA?

So if I source pings from the 'inside' to another interface called 'testint':

'Routing failed to locate next hop for icmp'

Both interfaces are directly connected to the ASA.

Any help is much appreciated thanks!

Dean

1 Accepted Solution

Accepted Solutions

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi Dean,

By design ASA would not allow you to ping an interface IP if you come from a different interface.

For security purposes the security appliance does not support far-end interface ping, that is pinging the IP address of the outside interface from the inside network.


Here is the document for the same:


http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/asdm63/configuration_guide/config/access_management.html#wp1214986

Regards,

Aditya

Please rate helpful posts and mark correct answers.

View solution in original post

1 Reply 1

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi Dean,

By design ASA would not allow you to ping an interface IP if you come from a different interface.

For security purposes the security appliance does not support far-end interface ping, that is pinging the IP address of the outside interface from the inside network.


Here is the document for the same:


http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/asdm63/configuration_guide/config/access_management.html#wp1214986

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Review Cisco Networking for a $25 gift card