cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2311
Views
14
Helpful
17
Replies

Unable to ping outside interfaces on FTDs (IOS 7.2.5)

Ditter
Level 4
Level 4

Hi, never found why i can not ping outside marked interfaces on FTD device although via platform settings this is open.

Please refer to the attached screeshot.

Thanks,

Ditter.

17 Replies 17

As mentioned by others here, you cannot ping an FTD interface that is not the ingress interface.  If you want to control ICMP packets that are arriving on a specific interface and are destined for the FTD itself, you can use the ICMP menu / ICMP access list to control this traffic.

--
Please remember to select a correct answer and rate helpful posts

to visualize it:

KarstenIwen_0-1708417739635.png

On each interface, you can use the mentioned platform settings to control which ICMP types are processed. Perhaps you don't want the FTD to be pinged, but you want to allow the FTD itself to ping out of the interface. 

As the others mentioned, the use of the ICMP menu is to allow or deny specific ICMP types on an interface. However, the traffic flow should always be coming from a source on the same segment as the interface. A source on the outside segment can ping the firewall outside interface, a source on the inside segment can ping the firewall inside interface, and so on.

Review Cisco Networking for a $25 gift card