cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
18553
Views
0
Helpful
3
Replies

loopback interface in ASA or FWSM

snarayanaraju
Level 4
Level 4

Hi experts,

Is it possible to create loopback interfaces in FWSM or ASA firewall

The need is i want a interface command to the firewall as I am facing problem in pinging one interface IP ADDRESS from the other zones.

Thanks in advance

sairam

3 Replies 3

Kevin Redmon
Cisco Employee
Cisco Employee

Sairam,

No - Cisco firewalls do NOT allow for a loopback address. If you are having issues with pinging a certain interface IP address, please be sure that you are pinging the interface closest to the client machine - ie NOT another interface. Unlike a router, the Cisco firewalls do NOT allow you to ping a "far-side" interface. Also, be sure that you have 'icmp permit ' for the relevant interface.

Not entirely true. You can issue the 'management-access inside' command, which will enable you to SSH and issue ping/snmp commands on the inside interface IP eg. from the far-end of a IPsec tunnel configured.

"Also, be sure that you have 'icmp permit ' for the relevant interface"

This is NOT true. Pix/ASA, by default, will let you ping the interface, unless explicitly dennied.

Review Cisco Networking products for a $25 gift card