02-25-2014 05:56 PM - edited 03-04-2019 10:26 PM
Hello, have had this issue for a while I assume. But in any case, we have a Cisco ASR 1002 on the edge that does our routing and NAT, behind that we have a Cisco ASA 5585-X and then our LAN.
Trying ping 208.76.142.234 fails from my desktop behind the firewall, although I see the flow being created in the log for the ICMP packet. I also see the NAT translation on the edge router happening using show ip nat trans | inc 208.76.142.234.
I can however ping this IP from the edge router and the firewall.
I am attaching a doc that explains it better. You can also normally ping this IP from any other location, ex my cell phone.
Any ideas?
02-25-2014 11:37 PM
Hello, Jeremy.
I guess your ASA could have/miss ACL that blocked ICMP echo-reply back to LAN (inspect icmp could be one more way to fix the issue).
PS: it's a little strange that you run NAT on ASR and not ASA device.
02-27-2014 09:38 AM
Here is a packet cap from the ASR. Looks like someone is dropping our traffic..
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide