08-21-2009 10:27 PM - edited 03-11-2019 09:08 AM
Hi experts,
Is it possible to create loopback interfaces in FWSM or ASA firewall
The need is i want a interface command to the firewall as I am facing problem in pinging one interface IP ADDRESS from the other zones.
Thanks in advance
sairam
08-23-2009 06:21 AM
Sairam,
No - Cisco firewalls do NOT allow for a loopback address. If you are having issues with pinging a certain interface IP address, please be sure that you are pinging the interface closest to the client machine - ie NOT another interface. Unlike a router, the Cisco firewalls do NOT allow you to ping a "far-side" interface. Also, be sure that you have 'icmp permit
10-24-2009 03:03 AM
Not entirely true. You can issue the 'management-access inside' command, which will enable you to SSH and issue ping/snmp commands on the inside interface IP eg. from the far-end of a IPsec tunnel configured.
10-24-2009 03:16 PM
"Also, be sure that you have 'icmp permit
This is NOT true. Pix/ASA, by default, will let you ping the interface, unless explicitly dennied.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide