03-11-2022 03:09 AM
Dear All,
I'm trying to add Unifi Security Gateway to a Cisco ASA that is already configured, I want to have ASA as a second layer of security since the licenses of the URL filtering and malware protection have expired, so I want to add Unifi Security Gateway and have ASA as a second layer of security.
I have a Cisco Coreswitch that has the ASA as its default gateway, and the default gateway of the ASA is the Unifi Security Gateway. Cisco Coreswitch is connected to port 2 of the ASA where as port 3 of the ASA is connected to the USG. I'm able to ping from the coreswitch to port 2 since they're directly connected whereas I can't ping port 3 on the ASA which is connected to the USG.
I gave Cisco Coreswitch Port an IP of 192.168.1.1 and the Cisco ASA port 3 192.168.1.2, on the ASA I gave port 3 an IP of 192.168.10.1 and on the USG port an IP of 192.168.10.2.
I'm not having connection from the ASA to the USG. Coreswitch can only see port 2 on the ASA.
What could be the problem?
Thanks in advance!
03-11-2022 03:36 AM - edited 03-11-2022 03:41 AM
@AhmadZ are you pinging the ASA's interface 3 from the core switch? If so you cannot be connected to one ASA interface and ping through the ASA to the ASA's far interface, that is by design.
If you cannot ping the USG you either need to configure inbound ACL on the outside ASA interface or run the command fixup protocol icmp to inspect icmp traffic.
03-11-2022 03:43 AM
Yes, I'm trying to ping ASA interface 3 (which is connected to USG) from the coreswitch.
what I need is to have traffic between coreswitch and USG, because I'm not able to access internet on the coreswitch through USG where my IPS are connected to the USG.
03-11-2022 03:53 AM - edited 03-11-2022 04:00 AM
@AhmadZ The USG possibly won't know about the local networks behind the ASA, so you may need routes on the USG or just NAT behind the ASA.
03-11-2022 04:31 AM
@Rob Ingram I've done static routes on the USG, but still same issue
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide