cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
454
Views
0
Helpful
8
Replies

Multiple VLAN Configuration over ASA Firewall into DMZ

jonasvanessen
Level 1
Level 1

I'm a complete beginner with Cisco Packet Tracer.

I somehow cannot ping inside my dmz for some reason?

Any help is appreciated.

Kind regards

Jonas

1 Accepted Solution

Accepted Solutions

M02@rt37
VIP
VIP

Hello @jonasvanessen 

some issues...

M02rt37_0-1702389768820.png

ASA interfaces (red circle) are with IP address (L3) and on their respective Switches facing these 2 interfaces your are in Trunk mode...

Also your Multilayer Switch (L3) has got no route !

Servers on DMZ have got Gateway 10.0.0.1....where is this address ? On ASA you have on DMZ interface 10.0.0.2 configured.

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

View solution in original post

8 Replies 8

This is by design. You only can ping the interface that is near to you. If your device is on the inside network, you can ping the inside interface but not the dmz interface. If you are on the dmz, you can ping the dmz interface but not the inside interface.

I sadly cannot ping from vlan10/20 to vlan30 nor vice versa

are they use same security level ?

yes, just to make it easier i've put both on security-level 100, see the .zip

I can not open zip

If same level 

Then add

same secuirty level permit intra interface 

Same secuirty level permit inter interface 

MHM

add icmp inspection 
or add ACL to allow ICMP 
MHM

M02@rt37
VIP
VIP

Hello @jonasvanessen 

some issues...

M02rt37_0-1702389768820.png

ASA interfaces (red circle) are with IP address (L3) and on their respective Switches facing these 2 interfaces your are in Trunk mode...

Also your Multilayer Switch (L3) has got no route !

Servers on DMZ have got Gateway 10.0.0.1....where is this address ? On ASA you have on DMZ interface 10.0.0.2 configured.

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

Hi M02@rt37,

Thanks for your detailled feedback. I tried to implement all the points from your input, but sadly failed in getting it to work. Nevertheless i guess you are right, i think i just lack some basic understanding in certain areas, in order to get it to work.

Thanks & Kind regards

Jonas 

Review Cisco Networking for a $25 gift card