cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1497
Views
0
Helpful
5
Replies

cannot ping external servers like yahoo or sony

benedict dcunha
Level 1
Level 1

dear All,

I have installed quite recently a cisco ASA 5520 replacing a linux based firewall

I have only 2 zones ..

one is internal netowrk and other external

the internal network has web servers, dns and mail server all having public IPs

Every thing is OK but i have seen that if I try to ping an external server for example www.yahoo.com

i cannot ping says

------

[sylvan@kmdns1 ~]$ ping www.yahoo.com

PING eu-fp.wa1.b.yahoo.com (87.248.112.181) 56(84) bytes of data.

--- eu-fp.wa1.b.yahoo.com ping statistics ---

6 packets transmitted, 0 received, 100% packet loss, time 5010ms

----------

but I can ping  from systems which are outside my firewall perfectly

with the linux firewall i had before i could ping perfectly to yahoo from any of my internal servers

apprecite your advice and help

regards

simon

1 Accepted Solution

Accepted Solutions

Did you try fixup protocol icmp ?

Please post your configuration is that doesn't work.

Manish

View solution in original post

5 Replies 5

manish arora
Level 6
Level 6

Try :-

asa(config)# fixup protocol icmp

Manish

varrao
Level 10
Level 10

Hi Benedict,

A littlt bit insight into your configuration would be helpful, if you can share (edit it as required).Otherwise difficult to guess, try pinging 4.2.2.2 and instead of the url, try the ip of yahoo (72.30.2.43) and verify if it is a dns issue. Are you able to access internet?????

Thanks,

Varun

Thanks,
Varun Rao

Dear Guys,

really apprecite and thanks guys for the ultra fast reply...

by the way just forgot to metion

if I telnet from one of my internal server to the firewall and do

KMUN-ASA# ping www.sony.com

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 72.52.6.10, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 190/200/210 ms

it works fine

but from my dns server  or my mail server i see

---------------

sylvan@kmdns2 ~]$ ping www.yahoo.com

PING eu-fp.wa1.b.yahoo.com (87.248.112.181) 56(84) bytes of data.

--- eu-fp.wa1.b.yahoo.com ping statistics ---

20 packets transmitted, 0 received, 100% packet loss, time 19009ms

[sylvan@kmdns2 ~]$ ping 87.248.112.181

PING 87.248.112.181 (87.248.112.181) 56(84) bytes of data.

--- 87.248.112.181 ping statistics ---

4 packets transmitted, 0 received, 100% packet loss, time 3006ms

-----------

By the way all service are working fine

apprecite your help..

regards

simon

Did you try fixup protocol icmp ?

Please post your configuration is that doesn't work.

Manish

dear Mani,

First let me apolozije for not reply you early since I got stuck with some personal work.

I tried the fixup protocol icmp and woww it worked like a charm.

thnks once again and really apprecite

may god bless u

regards

simon

Review Cisco Networking for a $25 gift card