cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
612
Views
0
Helpful
6
Replies

Routing in FTD

deypuchka
Level 1
Level 1

Hello guys I am new in this community, So I have this topology, I have assigned all the IPs correctly and I am using OSPF routing protocol on all the devices. When I check the routing tables of all the devices also network is showing all the routes. but the problem is I cannot ping from PC3(172.10.1.20) to Internet(L0: 8.8.8.8).

Connections from

OUTSIDE1-> Internet is working.

OUTSIDE2-> Internet is working.

FTD(192.168.15.100)-> Internet is working.

Also in the FTD I have given OPSF ROUTING and Access-list.

 

1.PNG

6 Replies 6

deypuchka
Level 1
Level 1

The Core Switch also is showing all the routes but not able to ping to the internet. I can either shutdown e0/0 or f1/0 port of the Internet router. But only one port will work not two.

Hello,

 

post the full running configurations of both routers, the core switch, as well as the FTD device in the path (the one on the left).

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello @deypuchka ,

 

 
 
 

>>

So I have this topology, I have assigned all the IPs correctly and I am using OSPF routing protocol on all the devices. When I check the routing tables of all the devices also network is showing all the routes. but the problem is I cannot ping from PC3(172.10.1.20) to Internet(L0: 8.8.8.8).

Connections from

OUTSIDE1-> Internet is working.

 

message 2 >>

The Core Switch also is showing all the routes but not able to ping to the internet. I can either shutdown e0/0 or f1/0 port of the Internet router. But only one port will work not two.

 

As FTD is a Firewall a NG FW you should have also configured NAT and you need to choice a primary uplink   load balacing is supported only if the two next-hops are reachable via the same outside X interface , load balancing over Outiside1 and Outside 2 is not supported.

 

@Marvin Rhoads can you confim ?

 

Hope to help

Giuseppe

 

 

 

OUTSIDE2-> Internet is working.

FTD(192.168.15.100)-> Internet is working.

Also in the FTD I have given OPSF ROUTING and Access-list.

 

balaji.bandi
Hall of Fame
Hall of Fame

Quick question is the 8.8.8.8 real google IP you trying to ping, this is in the Lab dummy created IP

 

if the real one, then you need NAT to reach 8.8.8.8 IP

if this is dummy then, from outside1 and 2, are you able to reach VPC IP 172.10.1.20 ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

It is dummy and yes I can ping from Outside 1 and 2 to 172.10.1.20.

Ping need default ICMP inception to allow ping pass through ASA.