04-05-2012 07:05 PM - edited 03-11-2019 03:51 PM
Hi all,
I need to able to ping Cisco ASA inside interface IP from outside connected network.Basicaly outside interface connected to private link to HQ. Now we would link to monitor connection from HQ to branch by pinging Branch ASA inside interface IP from HQ Monitoring Server. By default ASA dont allow that. Anyway to achieve this?
(inside-interface)Cisco ASA at Branch(outside interface) <----->Private Link <-----> HQ
04-05-2012 08:31 PM
You can't ping through the firewall to one of its interfaces.
Take a look at this doc.
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic5
hth
Chad
Sent from Cisco Technical Support iPad App
04-05-2012 10:36 PM
you can a) setup a monitoring only ipsec vpn tunnel and add "management-access inside" if you REALLY need to ping or b) if you only need to monitor the inside interface status, you can just ping a device on the internal network like a switch or server. after all, you only want to check if the LAN side is up right?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide