Ping works from ASA to remote network but not from PCs behind ASA

Unanswered Question
Dec 2nd, 2007
User Badges:

We have a joint venture with a company who has started to take IT into their own hands. Unfortunately they still need access to many of our systems. They recently installed an ASA 5505 with their own internet connection. They are also connected to us via Sprint MPLS and a Cisco 2801 we have on site ( I have a static route in the ASA directing any traffic for to Pinging works fine from the ASA but none of the PCs behind the ASA can ping anything in the network. To get it to work I had to add a manual route add command on the Windows XP machine. The client PCs use the ASA as their default gateway so I would assume it would just know to forward any request for to I've attached the config for the ASA on site there. I'm thinking this might be something to do with NAT since when I try to ping from a PC that ASA spits out something about "no translation group...."

I appreciate any help.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
jeremyault Sun, 12/02/2007 - 17:23
User Badges:

I could be wrong but I think you need a NAT exception for traffic from the 10 network to the 192 network.

Try this:

access-list NONAT permit ip

nat (inside) 0 access-list NONAT

henryrohlfs Sun, 12/30/2007 - 18:46
User Badges:

I'm curious if this worked since I have a similar problem routing to a second network on my inside interface.

srue Sun, 12/30/2007 - 21:07
User Badges:
  • Blue, 1500 points or more

either turn on icmp inspection, or explicity allow echo-reply traffic back in to the ping source.

jimgrumbles Thu, 01/03/2008 - 15:35
User Badges:

Sorry about the lack of response. It looks like the way the remote technician setup the PC for me to access was on a separate network. I had assumed he had it on the same network as all the other PCs but apparently not, they were working normally. Thank you for the responses.


This Discussion