11-01-2011 01:02 AM - edited 03-11-2019 02:44 PM
I have a two ASA, in active / standby failover status.
In the ASA there has two context, one is ASA1 and the other is ASA2
A network 10.10.1.0/24 is between these two context
I tried to do a ping test in a client behind ASA2, ping to ASA1 client, failed with question marks, I checked the access rule is correct, the static route for dedication subnet is enabled in these two ASA context
Result of the command: "ping 192.168.3.2"
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.3.2, timeout is 2 seconds:
?????
Success rate is 0 percent (0/5)
Anyone know what's that mean? I checked on the internet that say it's "Unknow Packet", but what will cause this issue? Thanks!
11-01-2011 04:50 AM
Hi! This means sipmly timeout. No response was recieved in 2 seconds interval.
__
HTH
11-01-2011 06:00 AM
Hi Chun,
it means that either there is no route to the destination or the firewall is blocking it.
Can you do a traceroute to the destination and where it stops?
Regards
Kishore
11-01-2011 08:24 AM
I think you may need to add the intended source interface name. Something like "ping inside 192.168.3.2".
Brian
02-20-2017 02:03 AM
I think need to insert
icmp permit any <Interface name>
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide