cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1584
Views
0
Helpful
7
Replies

ASA | Unable to ping public IP

John
Level 1
Level 1

We are unable to ping the public ip ( which is translated IP) from from internal network?

7 Replies 7

Aditya Ganjoo
Level 9
Level 9

Hi John,

By design you cannot ping the ASA interface IP coming from a different interface.

So if you are behind the inside interface you cannot ping the outside IP of the ASA.

Regards,

Aditya


Please rate helpful posts and mark correct answers.

Thank's Aditya

Is there any cisco documents?

Hi John

Please refer to the following doc:

http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/15246-31.html#pingsown

Check the pinging Another Interface section.

Also you can check these link:

https://learningnetwork.cisco.com/thread/7355

Regards,

Aditya

Please rate helpful posts.

Hello Aditya,

How about this forum? 

https://supportforums.cisco.com/discussion/12403546/cisco-asa-5510-cannot-reach-public-ips-inside-network

how to configure to ping public IP's from Inside Network?

Hi John,

This is a different case.

You can ping any public IP from the inside network if you have the correct rules in place.

If you enable icmp inspection on ASA you would be able to ping the IP's from the inside network.

To enable icmp inspection on ASA use this command--- fixup protocol icmp

Regards,

Aditya

example: for static nat configuration:

internal 192.168.1.1 (translated ip 121.68.1.2)

outside: 121.68.1.1

we have a public ip (which is translated ip),  we would like to know from internal (192.168.1.1) can we ping the translated ip 9121.68.1.2?

we already allowed icmp inspection in our firewall.

Hi John,

You should be able to ping the NAT IP from the inside.

Could you please run  packet tracer  to check the flow of the traffic on the ASA ?

Regards,

Aditya

Review Cisco Networking for a $25 gift card