05-03-2016 07:02 AM - edited 03-12-2019 12:41 AM
We are unable to ping the public ip ( which is translated IP) from from internal network?
05-03-2016 07:24 AM
Hi John,
By
So if you are behind the inside interface you cannot ping the outside IP of the ASA.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
05-03-2016 07:38 AM
Thank's Aditya
Is there any cisco documents?
05-03-2016 09:30 AM
Hi John
Please refer to the following doc:
http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/15246-31.html#pingsown
Check the pinging Another Interface section.
https://learningnetwork.cisco.com/thread/7355
Aditya
Please rate helpful posts.
05-03-2016 07:03 PM
Hello Aditya,
How about this forum?
https://supportforums.cisco.com/discussion/12403546/cisco-asa-5510-cannot-reach-public-ips-inside-network
how to configure to ping public IP's from Inside Network?
05-03-2016 07:14 PM
Hi John,
This is a different case.
You can ping any public IP from the inside network if you have the correct rules in place.
If you enable
To enable
Regards,
Aditya
05-03-2016 07:51 PM
example: for static nat configuration:
internal 192.168.1.1 (translated ip 121.68.1.2)
outside: 121.68.1.1
we have a public ip (which is translated ip), we would like to know from internal (192.168.1.1) can we ping the translated ip 9121.68.1.2?
we already allowed icmp inspection in our firewall.
05-03-2016 08:03 PM
Hi John,
You should be able to ping the NAT IP from the inside.
Could you please run packet tracer to check the flow of the traffic on the ASA ?
Regards,
Aditya
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide