cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
605
Views
0
Helpful
1
Replies

Can't PING IP Address Route Firewall?

williammanurung
Level 1
Level 1

Hai guys,

 

I have asa with routed firewall mode.

and i have configured interface like this:

 

interface Port-channel2.3111
 nameif OUTSIDE
 security-level 0
 ip address 1.1.1.1 255.255.255.0 standby 1.1.1.2

 


And what i still confused is, why 1.1.1.1 or 1.1.1.2 cannot ping from different segment?
I have no problem with routing in firewall

1 Reply 1

Hello,

 For security reason.  When ping is disabled, a bunch of  malicious tools can´t track you.

 You can try enablig inspection and also permiting icmp.

 

policy-map global_policy
class inspection_default
inspect dns migrated_dns_map_1
inspect icmp

 

permit icmp OUTSIDE in

Review Cisco Networking for a $25 gift card