cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4239
Views
0
Helpful
6
Replies

Enable Ping interface WAN (Firepower FMC)

Hello, I am trying to ping the WAN interface of a Firepower in a laboratory and it blocks the traffic.

I have another firepower but this one is not added to the FMC and the ping works without problem, I already enabled the ping in the FMC and created a rule that allows everything and it doesn't work.

 

 

6 Replies 6

@FranciscoOpenLink

Ping would be permitted as default to the FTD.

Where did you configure the ping rules? ICMP (ping) is controlled via the Platform Settings not the Access Control Policy (ACP).

Where are you pinging from?

What interface are you connected to?

You'd only be able to ping the WAN interface if you were connected behind that interface, you could not be connected behind another FTD interface (i.e., INSIDE) and ping the WAN interface, that will not work by design.

Hello, I am pinging from another Firepower that I have connected via WAN on the same network segment.

I show you the rules I create

foto ICMP.png 

 

foto reglas.png

firepower 1.png

 

connect a virtual machine to that interface to check and it doesn't work either.

 

ping otra pc.png

@FranciscoOpenLink what is the configuration of the ICMP service "permitICMP"? if it's incorrect, there is an implicit deny, so the traffic will be dropped.

 

The ACP policy is not applicable when controlling traffic to the FTD's interface.

I am allowing ICMP in that policy

 

 

 

permitir ICMP.png

 

 

permit icmp 2.png

some times the PC OS FW drop ICMP, disable FW or allow ping.

Review Cisco Networking products for a $25 gift card