ASA 5510 Virtual IP & Sub-Interfaces

Unanswered Question
Aug 30th, 2007

Hi All,

I have a server farm on my DMZ. I have statically NATted the Servers' IP addresses to other IP addresses for the inside & outside networks. I can http in to web server's NATted IP, but i cannot ping these addresses. Is there a way i can ping these virtual addresses.

Can i use the subinterfaces on say the outside or inside interfaces to assign public IPs and then map the addresses of the servers on DMZ to those on the subinterfaces.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
purohit_810 Thu, 08/30/2007 - 05:40

Yes you can do but in that case your all OUTSIDE INterface has priority will be 0.

Open Access list ICMP extended to ping.



srue Thu, 08/30/2007 - 09:00

To allow inbound pings, you must specify on your outside acl:

permit icmp any any echo

To allow outbound pings (the return response), again, on your outside acl:

permit icmp any any echo-reply

These assume you have no outbound acl's.

The other option, turn on icmp inspection.


This Discussion