07-06-2022 03:09 PM
I am stumped why is it I can ping from a host in Site A connected to FTD inside interface to a host in Site B ASA inside interface over S2S tunnel but I cannot ping from either side from the FTD or ASA. The FTD IP addresses for management and inside are on same subnet along with the host that I can ping from. This makes no sense
07-06-2022 08:35 PM
try configuring
management-access <interface-name>
to inside interface
07-06-2022 11:40 PM
@keithcclark71 that's by design on both the ASA and FTD. The ASA/FTD only responds to ICMP traffic sent to the interface that traffic comes in on; you cannot send ICMP traffic through an interface to a far interface. Reference here.
The only exception is over a VPN, in which case you need to configure the mangement-access command already provided. You cannot configure this natively on the FTD, you have to use FlexConfig to apply the same command.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide