03-28-2022 11:10 PM
Hello guys I am new in this community, So I have this topology, I have assigned all the IPs correctly and I am using OSPF routing protocol on all the devices. When I check the routing tables of all the devices also network is showing all the routes. but the problem is I cannot ping from PC3(172.10.1.20) to Internet(L0: 8.8.8.8).
Connections from
OUTSIDE1-> Internet is working.
OUTSIDE2-> Internet is working.
FTD(192.168.15.100)-> Internet is working.
Also in the FTD I have given OPSF ROUTING and Access-list.
03-28-2022 11:28 PM
The Core Switch also is showing all the routes but not able to ping to the internet. I can either shutdown e0/0 or f1/0 port of the Internet router. But only one port will work not two.
03-28-2022 11:43 PM
Hello,
post the full running configurations of both routers, the core switch, as well as the FTD device in the path (the one on the left).
03-29-2022 12:01 AM
Hello @deypuchka ,
>>
So I have this topology, I have assigned all the IPs correctly and I am using OSPF routing protocol on all the devices. When I check the routing tables of all the devices also network is showing all the routes. but the problem is I cannot ping from PC3(172.10.1.20) to Internet(L0: 8.8.8.8).
Connections from
OUTSIDE1-> Internet is working.
message 2 >>
The Core Switch also is showing all the routes but not able to ping to the internet. I can either shutdown e0/0 or f1/0 port of the Internet router. But only one port will work not two.
As FTD is a Firewall a NG FW you should have also configured NAT and you need to choice a primary uplink load balacing is supported only if the two next-hops are reachable via the same outside X interface , load balancing over Outiside1 and Outside 2 is not supported.
@Marvin Rhoads can you confim ?
Hope to help
Giuseppe
OUTSIDE2-> Internet is working.
FTD(192.168.15.100)-> Internet is working.
Also in the FTD I have given OPSF ROUTING and Access-list.
03-29-2022 12:02 AM
Quick question is the 8.8.8.8 real google IP you trying to ping, this is in the Lab dummy created IP
if the real one, then you need NAT to reach 8.8.8.8 IP
if this is dummy then, from outside1 and 2, are you able to reach VPC IP 172.10.1.20 ?
03-29-2022 12:16 AM
It is dummy and yes I can ping from Outside 1 and 2 to 172.10.1.20.
03-29-2022 05:28 AM
Ping need default ICMP inception to allow ping pass through ASA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide