10-04-2018 11:18 AM - edited 02-21-2020 08:19 AM
Please see attached document cant ping through firewall in DMZ with two ASA's
Thanks
10-04-2018 11:38 AM - edited 10-04-2018 11:39 AM
Hi,
Ping/ICMP is blocked on ASA by default. Try this:-
ASA(config)# policy-map global_policy
ASA(config-pmap)# class default-inspection-class
ASA(config-pmap-c)# inspect icmp
or
ASA(config)# fixup protocol icmp
HTH
10-04-2018 11:50 AM
Hi
Already added to both Firewalls, any more ideas.??
Thanks
10-04-2018 12:00 PM
10-04-2018 12:12 PM
Hi
No nat, I can ping from the outside interface of the inside firewall =.2 to the internet facing firewall inside interface =.1 these are on same subnet connected to 3850, but i cannot ping from inside firewall beyond .2 of internet firewall, and i cannot ping from internet facing firewall .2 through to public address on outside interface of internet facing firewall, i have a default route poing outside interface any any, when i try putting a route on inside firewall pointing to .2 it says its a connected interface. what routes are needed and where please.?? could it be because the firewalls have an interface in same subnet.??
Thanks
10-04-2018 12:17 PM
10-04-2018 12:35 PM
10-04-2018 01:20 PM
10-04-2018 01:30 PM
Hi Thanks for that,
so nat inside traffic to outside interface, any thoughts on traffic coming from inside firewall 172.20.57.1 to internet because that also fails.??
Thanks
10-04-2018 01:41 PM
10-04-2018 01:46 PM
Hi
Its not letting me add this route outside 0 0 172.20.57.2 it says its a connected network.??
10-04-2018 01:58 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: