cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
711
Views
5
Helpful
2
Replies

Cannot Ping into an ASA 5506

Skawilly1
Level 1
Level 1

I have searched the forums and all the answers I have seen I have implemented. 

 

When I ping into the ASA's outside (WAN) interface, I can see on the log it is getting denied. I have added an ACL for coming in to the outside interface to allow ICMP.

I  have added the ICMP to the global inspection with fixup protocol ICMP.

But when I ping the outside interface I see it is getting 'denied by interface outside'. 

 

ASA 9.2

 

Thanks.

2 Replies 2

Greg Smalley
Level 1
Level 1

icmp permit ip_address net_mask if_name

Marvin Rhoads
Hall of Fame
Hall of Fame

In addition to what @Greg Smalley correctly suggested, remember these two things:

 

1. An ACL applied to an interface via an access-group is for traffic THROUGH the interface, not traffic TO that interface.

2. The inspections in your policy map / class map are similarly for traffic through the firewall.

Review Cisco Networking for a $25 gift card