05-18-2013 11:23 PM - edited 03-11-2019 06:46 PM
Hello Friends,
I have a problem pinging the virtual ip's of NLB from hosts of differrent subnets.
The Scenario is as below
Server Farm --- Cisco ASA Firewall (Internal Firewall) --- Lan Network --- Edge
All my servers reside in Server Farm which is behind the internal firewall. The server services dept are tryig to have a NLB for the few servers. Now the porblem is that the user (diff Vlan) is able to ping the physical ip of the server but not the virtual ip.
Can some one please provide the solution to this prolem?
05-19-2013 06:48 AM
Hi,
Couple of checks- ICMP allowed on firewall for virtual IPs? VIP showing up and reachable from server farm IPs? Also, NLB had any rules with ref to icmp related services/replies?
Thx
MS
05-19-2013 07:36 AM
Hi MS,
Thanks for your response.
Yes, ICMP is allowed on the firewall for the virtual IP's and is also pingable from the firewall and the server farm, but the problem is the virtual ip's are not pingable from other subnets other than the server Vlan.
NLB has no rules with referrence to icmp.
Regards,
Ahmed
05-19-2013 10:55 AM
Hi Ahmed,
Try enabling 'debug icmp trace' (or debug icmp trace 128) on ASA and try to ping the VIP. Check for icmp each & echo-reply. if you see both on ASA and ping fails,I guess, issue is somewhere else in the path.
Thx
MS
05-20-2013 05:56 AM
Hi MS,
The results are as below when the debug is enabled:
The virtual ip is not seen in the debug list as it was not pinging from the user Vlan but pings ok from the server Vlan. Once the virtual ip is swapped with the physical ip, the pings are on from the user Vlan.
Next swap it back to the virtual ip, the ping continues to be ok from the user vlan.
So, in order to make the virtual ip work, I had to make it physical and then to virtual. By doing this I could see both physical and virtual ip's in the debug list.
Not sure how to fix this?
Regards,
Ahmed
05-20-2013 06:19 AM
Hi Ahmed,
Not sure what NLB in place, but below is some informational link on Microsoft..
I will reach out to NLB support , to make sure that there is no bug in the NLB OS version.
Thx
MS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide