11-01-2019 03:24 AM
Hi guys,
I am having issues pinging my FTD internal interfaces. I can actually ping WAN interface, no issue there. But for LAN interface packet tracer says "no route". I can ping the hosts inside the LAN. There are no specific ICMP rules in Device Platform Policy on FMC. Any suggestions?
10.50.31.97/27 is my LAN interface.
Trace to host inside LAN:
> packet-tracer input WAN icmp 10.11.28.169 0 0 10.50.31.97
Result:
input-interface: WAN
input-status: up
input-line-status: up
Action: drop
Drop-reason: (no-route) No route to host
> packet-tracer input WAN icmp 10.11.28.169 0 0 10.50.31.98
Phase: 1
Type: ROUTE-LOOKUP
Subtype: Resolve Egress Interface
Result: ALLOW
Config:
Additional Information:
found next-hop 10.50.31.98 using egress ifc LAN
Phase: 2
Type: ACCESS-LIST
Subtype: log
Result: ALLOW
Config:
..etc
Trace to WAN interface:
> packet-tracer input WAN icmp 10.11.28.169 0 0 10.11.39.106
Phase: 1
Type: ROUTE-LOOKUP
Subtype: Resolve Egress Interface
Result: ALLOW
Config:
Additional Information:
found next-hop 10.11.39.106 using egress ifc identity
..etc
Thanks.
Solved! Go to Solution.
11-01-2019 03:40 AM
11-01-2019 03:40 AM
11-01-2019 03:45 AM
Ah, missed that ;-)
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide