cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1818
Views
5
Helpful
3
Replies

Configuring ASAv to send and receive ICMP

This is my first time configuring a virtualized ASA (9.8.1) in GNS3 for use in CCNAS class. The configuration is as follows:

ASAv g0/0 - 10.10.10.2   >  HUB   >  Loopback 10.10.10.1 (Local PC)

I'm trying to ping the Loopback address from the ASAv and vice versa. I know the loopback is in working order because I was able to ping it from a virtualized C7200 router.

I'd like to know the configurations in order to get the ASA ping and be ping-able 



Hub is used instead of switch because GNS3 ethernet switch is buggy 

1 Accepted Solution

Accepted Solutions

Thanks for the speedily reply. The Cloud in the topology represents the loopback address.
10.10.10.1 is the Loopback interface's configuration on the Windows side of the topology. I've used a router in place of the ASA prior to testing it with an ASA and it was reachable from both directions.

View solution in original post

3 Replies 3

Hello
I am assuming from you topology that the lan address is 10.10.10.1 and the loopback is another address?

Please try the below example:

interface GigabitEthernet0
nameif Inside
security-level 100
ip address 10.10.10.2 255.255.255.0

object network LAN1
subnet 10.10.10.0.255.255.255.0

object network LAN2
subnet (loopback address) 255.255.255.255

object-group network ICMP-ECHO
network-object object LAN1
network-object object LAN2

access-list 100 extended permit icmp any object-group ICMP-ECHO echo-reply

route Inside (loopback address) 255.255.255.255 10.10.10.1

res
paul


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Thanks for the speedily reply. The Cloud in the topology represents the loopback address.
10.10.10.1 is the Loopback interface's configuration on the Windows side of the topology. I've used a router in place of the ASA prior to testing it with an ASA and it was reachable from both directions.

[UPDATE]

After using the configurations mentioned above with the necessary adjustments pinging to and from the ASA was unsuccessful



Once again I'd like to clarify that my Windows-side firewall is allowing ICMPs both to and from itself (host) this is a matter of the ASA requiring necessary configurations to allow ICMP both out and in from within the local network.
Both networks Windows-side and in the virtualized environment are within the same subnet.

Thanks in advance