cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
404
Views
0
Helpful
3
Replies

unable to ping Switch behind directly connected ASA

mahesh18
Level 6
Level 6

 

Hi Everyone,

 

Here is setup ASA1-e0/0----192.168.1.171----------------e0/0---192.168.1.174  ---ASA2-----et0/1----10.2.0.1------fa1/0/1------10.2.0.2---Switch

I am pinging from ASA1

 

ASA1#  ping 10.2.0.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.2.0.2, timeout is 2 seconds:
?????
Success rate is 0 percent (0/5)


Logs show

Nov 26 2014 21:24:26: %ASA-6-302020: Built outbound ICMP connection for faddr 10.2.0.2/0 gaddr 192.168.1.171/56999 laddr 192.168.1.171/56999

Nov 26 2014 21:24:36: %ASA-6-302021: Teardown ICMP connection for faddr 10.2.0.2/0 gaddr 192.168.1.171/56999 laddr 192.168.1.171/56999

 

ASA2 logs

 

Nov 26 2014 21:28:43: %ASA-6-302020: Built inbound ICMP connection for faddr 192.168.1.171/9199 gaddr 10.2.0.2/0 laddr 10.2.0.2/0
Nov 26 2014 21:28:53: %ASA-6-302021: Teardown ICMP connection for faddr 192.168.1.171/9199 gaddr 10.2.0.2/0 laddr 10.2.0.2/0

 

 

Is this default behaviour ? or

i need some config change to fix this?

 

 

Regards

Mahesh

 

3 Replies 3

Srinath R
Level 1
Level 1

Hi Mahesh,

 

Can you please check if you have ICMP inspect on ASA2?

You should see "inspect icmp" in the output of "show run policy-map" under the global_policy.

If not, then run "fixup protocol icmp" from config mode and try again. If it still fails, please attach 'show tech' from both ASAs.

 

Regards,

Srinath

 

Hi Srinath,

 

ASA2 has incmp inspect enabled.

These ASA's are in my home lab.

Can this be due to nating?

Regards

Mahesh

Hi Mahesh,

 

Could you please share the output of 'show tech' from both ASAs?

It would be easier to find the root cause from the outputs.

Based on the logs, it does not look like the ASA is dropping the packets.

 

Regards,

Srinath

Review Cisco Networking for a $25 gift card