cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
355
Views
10
Helpful
2
Replies

I am stumped

keithcclark71
Level 3
Level 3

I am stumped why is it I can ping from a host in Site A connected to FTD inside interface  to a host in Site B ASA inside interface over S2S tunnel but I cannot ping from either side from the  FTD or ASA.  The FTD IP addresses for management and inside are on same subnet along with the host that I can ping from. This makes no sense

2 Replies 2

try configuring

management-access <interface-name>

to inside interface

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

@keithcclark71 that's by design on both the ASA and FTD. The ASA/FTD only responds to ICMP traffic sent to the interface that traffic comes in on; you cannot send ICMP traffic through an interface to a far interface. Reference here.

 

The only exception is over a VPN, in which case you need to configure the mangement-access command already provided. You cannot configure this natively on the FTD, you have to use FlexConfig to apply the same command.

Review Cisco Networking for a $25 gift card