04-26-2013 08:07 AM - edited 03-11-2019 06:35 PM
Hello,
Scenario is that i cant ping a server on the dmz between two firewalls
I have a server on the dmz on cisco asa and it needs to ping a server on the dmz on the checkpoint network
dmz on cisco asa then goes to corporate network on the asa before it goes to the checkpoint firewall
I have routing between the checkpoint and asa dmz's
I can ping from corporate network to the server on checkpoint dmz
but i cant ping from the dmz on the cisco asa to the checkpoint dmz
i have routing in place and also allowed all services and all interfaces for now on my ACL
any ideas.
I think the issue is on the cisco asa dmz
thanks
Kevin
Solved! Go to Solution.
04-26-2013 09:52 AM
Hello Kevin,
I would say corporate security level interface is higher than the DMZ one, so you will need to add an ACL to permit the traffic
Do the following
packet-tracer input dmz icmp x.x.x.x ( DMZ_ASA_HOST ) 8 0 Y.Y.Y.Y ( Corporate SERVER ON checkpoint)
Post the results and pleasee remember to rate all of the helpful posts
04-26-2013 09:52 AM
Hello Kevin,
I would say corporate security level interface is higher than the DMZ one, so you will need to add an ACL to permit the traffic
Do the following
packet-tracer input dmz icmp x.x.x.x ( DMZ_ASA_HOST ) 8 0 Y.Y.Y.Y ( Corporate SERVER ON checkpoint)
Post the results and pleasee remember to rate all of the helpful posts
04-30-2013 02:57 AM
You are correct on this. The ACL i had was applied to the wrong interface and hence the traffic was going no where. The ACL on one firewall (Checkpoint) was ok but not on the Cisco ASA. Thats it sorted now though and i can ping the servers from both locations.
thanks
Kevin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide