05-27-2021 11:59 AM
Hello,
I have the following topology:
I am trying for the first time to configure the firewall-1(ASAv) on cml and I want to use a static ip address for the desktop-0-in, all the configurations guides i checked use dhcp. I have configured the firewall-1 as following:
int g0/0
ip address 192.168.1.1 255.255.255.0
nameif inside
security-level 100
no shut
int g0/1
ip address 209.165.200.226 255.255.255.252
nameif outside
security-level 0
no shut
exit
route outside 0.0.0.0 0.0.0.0 209.165.200.225
object network INSIDE-NET
subnet 192.168.1.0 255.255.255.0
nat (inside, outside) dynamic interface
exit
policy-map global_policy
class inspection_default
inspect imcp
-----------------------
When I ping from desktop-0-in to desktop-0-out the ping reaches the outside desktop and replies, the ping reaches the ASAv but the ping does not follow, obviously there is something missing to reach the inside pc but i don't know how to configure it.
The inside pc has the ip address: 192.168.1.10
Thanks.
Solved! Go to Solution.
05-27-2021 12:12 PM - edited 05-27-2021 12:13 PM
Plesae run packet-tracer on the ASA and provide the output for review.
packet-tracer input inside icmp 192.168.1.10 8 0 <desktop-0-out IP address>
How have you actually confirmed the ping reached the destination and the echo-reply reached the ASA?
05-27-2021 12:12 PM - edited 05-27-2021 12:13 PM
Plesae run packet-tracer on the ASA and provide the output for review.
packet-tracer input inside icmp 192.168.1.10 8 0 <desktop-0-out IP address>
How have you actually confirmed the ping reached the destination and the echo-reply reached the ASA?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide