cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
806
Views
0
Helpful
2
Replies

ASA 5510 Virtual IP & Sub-Interfaces

ansuman07
Level 1
Level 1

Hi All,

I have a server farm on my DMZ. I have statically NATted the Servers' IP addresses to other IP addresses for the inside & outside networks. I can http in to web server's NATted IP, but i cannot ping these addresses. Is there a way i can ping these virtual addresses.

Can i use the subinterfaces on say the outside or inside interfaces to assign public IPs and then map the addresses of the servers on DMZ to those on the subinterfaces.

2 Replies 2

purohit_810
Level 5
Level 5

Yes you can do but in that case your all OUTSIDE INterface has priority will be 0.

Open Access list ICMP extended to ping.

Regards,

Dharmesh

To allow inbound pings, you must specify on your outside acl:

permit icmp any any echo

To allow outbound pings (the return response), again, on your outside acl:

permit icmp any any echo-reply

These assume you have no outbound acl's.

The other option, turn on icmp inspection.

Review Cisco Networking products for a $25 gift card