02-16-2013 10:57 AM - edited 03-04-2019 07:02 PM
Hi Geeks,
following is my setup on ASA
interface GigabitEthernet0/1.20
vlan 20
nameif ABC
security-level 100
ip address 10.20.100.1 255.255.255.0
interface GigabitEthernet0/1.30
vlan 30
nameif XYZ
security-level 100
ip address 10.20.200.1 255.255.255.0
SWITCH
1) all the clients are connected via L2 switch
2) gig 0/1 is trunk
3) allowed vlan 20 and 30
1) when i ping 10.20.200.1 from a client PC with 10.20.100.X ip i dont get the ping working
2) but when i ping a client inside 10.20.200.x from the same client PC with 10.20.100.X IP it works
3) its only the ASA subinterface that i cant ping from different VLAN clients.
can someone let me know the issue ?
i have enabled the following
icmp permit any ABC
icmp permit any XYZ
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
still no luck
02-26-2013 03:29 AM
disable pc firewall.....
03-03-2013 10:48 PM
i think that should be true. it will not allow you to ping a interface that you dont belong to..... on ASA by the way
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide