cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2222
Views
4
Helpful
16
Replies

ICMP on ASA 5520 (8.6) subinterface

w.janarthanan
Level 1
Level 1

                   Hi Geeks,

following is my setup on ASA

interface GigabitEthernet0/1.20

vlan 20

nameif ABC

security-level 100

ip address 10.20.100.1 255.255.255.0

interface GigabitEthernet0/1.30

vlan 30

nameif XYZ

security-level 100

ip address 10.20.200.1 255.255.255.0

SWITCH

1) all the clients are connected via L2 switch

2) gig 0/1 is trunk

3) allowed vlan 20 and 30

1) when i ping 10.20.200.1 from a client PC with 10.20.100.X ip i dont get the ping working

2) but when i ping a client inside 10.20.200.x from the same client PC with 10.20.100.X IP it works

3) its only the ASA subinterface that i cant ping from different VLAN clients.

can someone let me know the issue ?

i have enabled the following

icmp permit any ABC

icmp permit any XYZ

same-security-traffic permit inter-interface

same-security-traffic permit intra-interface

still no luck

16 Replies 16

disable pc firewall.....

Jawad Mukhtar,

i think that should be true. it will not allow you to ping a interface that you dont belong to..... on ASA by the way

Review Cisco Networking for a $25 gift card