×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

No network connectivity on low-security interface...

Answered Question
Nov 14th, 2010
User Badges:

Hello all,


I have an ASA 5505 with several interfaces configured. One is my "outside", with a security level of 0, a "dmz", with a security level of 10, and the rest are "insides" with security levels of 100.


On every interface except that of the dmz, I can ping the gateway interface and get a response. For some reason on my DMZ interface, I can't. The goal is to get inbound FTP to work through a L2L vpn at the dmz, but at this point I can't even ping the gateway interface from a host on the dmz network.


I have a hardware link, and it doesn't matter whether I move the interface to a different switch-port or put a different host on that network.


Is there something I'm missing about how the ASA handles traffic on lower-security interfaces?


Please let me know if I need to provide more information.


Thanks!



Result of the command: "show run"

: Saved
:
ASA Version 8.2(3)
!
hostname officefw1
enable password XXXX encrypted
passwd XXXX encrypted
names
<names>

dns-guard
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
switchport access vlan 50
!
interface Ethernet0/2
switchport trunk allowed vlan 100,125,150,200
switchport trunk native vlan 1
switchport mode trunk
!
interface Ethernet0/3
switchport access vlan 250
!
interface Ethernet0/4
switchport access vlan 251
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
interface Vlan1
shutdown
nameif inside
security-level 100
no ip address
!
interface Vlan2
nameif outside
security-level 0
ip address 68.226.79.105 255.255.255.224
!
interface Vlan50
nameif dmz
security-level 10
ip address 192.158.50.1 255.255.255.0
!
interface Vlan100
nameif infrastructure
security-level 100
ip address 192.168.100.1 255.255.255.0
!
interface Vlan125
nameif voip
security-level 100
ip address 192.168.125.1 255.255.255.0
!
interface Vlan150
nameif soa
security-level 100
ip address 192.168.150.1 255.255.255.0
!
interface Vlan200
nameif itdev
security-level 100
ip address 192.168.200.1 255.255.255.0
!
interface Vlan250
nameif systems
security-level 100
ip address 192.168.250.1 255.255.255.0
!
interface Vlan251
nameif management
security-level 100
ip address 192.168.251.1 255.255.255.0
!
interface Vlan999
no nameif
no security-level
no ip address
!
boot system disk0:/asa823-k8.bin
ftp mode passive
clock timezone CST -6
clock summer-time CDT recurring
dns domain-lookup infrastructure
dns domain-lookup voip
dns domain-lookup soa
dns domain-lookup systems
dns domain-lookup management
dns server-group DefaultDNS
name-server <dns server>
name-server <dns server>
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
<object groups>

access-list soa_access_in extended permit object-group WindowsShares object-group office_FS_clients object-group office_FS_servers log
access-list soa_access_in extended permit object-group ActiveDirectoryAuth object-group office_AD_clients object-group office_AD_servers log
access-list soa_access_in extended permit object-group NetworkPrinting object-group office_Print_clients object-group office_Print_servers
access-list soa_access_in extended permit tcp object-group office_ITDev_WebServer_clients object-group office_ITDev_Web_servers object-group ITDev_Webserver_Ports
access-list soa_access_in extended permit tcp object-group office_JIRA_clients object-group office_JIRA_servers eq www
access-list soa_access_in extended permit tcp object-group office_Printer_WUI_clients object-group office_Print_servers eq www
access-list soa_access_in extended permit tcp object-group office_Jabber_clients object-group office_Jabber_servers object-group Jabber
access-list soa_access_in extended permit udp 192.168.150.0 255.255.255.0 object-group Outside_DNS eq domain
access-list soa_access_in extended permit tcp 192.168.150.0 255.255.255.0 any eq www
access-list soa_access_in extended permit tcp 192.168.150.0 255.255.255.0 any eq https
access-list soa_access_in extended permit object-group Communicator_Ports 192.168.150.0 255.255.255.0 host server
access-list soa_access_in extended permit udp 192.168.150.0 255.255.255.0 any eq isakmp
access-list soa_access_in extended permit udp 192.168.150.0 255.255.255.0 any eq 4500
access-list soa_access_in extended permit tcp host 192.168.150.14 host server eq 3389
access-list soa_access_in extended permit tcp host 192.168.150.14 object-group DM_INLINE_NETWORK_11
access-list outside_access_in extended permit tcp host DB101 host WWW2 object-group DM_INLINE_TCP_3
access-list itdev_access_in extended permit object-group ActiveDirectoryAuth object-group office_AD_clients object-group office_AD_servers
access-list itdev_access_in extended permit object-group WindowsShares object-group office_FS_clients object-group office_FS_servers
access-list itdev_access_in extended permit object-group NetworkPrinting object-group office_Print_clients object-group office_Print_servers
access-list itdev_access_in extended permit tcp object-group office_Jabber_clients object-group office_Jabber_servers object-group Jabber
access-list itdev_access_in extended permit tcp object-group office_JIRA_clients object-group office_JIRA_servers eq www
access-list itdev_access_in extended permit udp 192.168.200.0 255.255.255.0 object-group Outside_DNS eq domain
access-list itdev_access_in extended permit tcp 192.168.200.0 255.255.255.0 any eq www
access-list itdev_access_in extended permit tcp 192.168.200.0 255.255.255.0 any eq https
access-list itdev_access_in extended permit object-group Communicator_Ports 192.168.200.0 255.255.255.0 host server
access-list itdev_access_in extended permit tcp object-group DM_INLINE_NETWORK_10 object-group prod_DBServers eq sqlnet
access-list itdev_access_in extended permit tcp object-group DM_INLINE_NETWORK_15 object-group DM_INLINE_NETWORK_8 eq ssh
access-list itdev_access_in extended permit tcp object-group office_Developer_Workstations object-group prod_IQAServers object-group RDP
access-list itdev_access_in extended permit tcp host Justin_PC host WWW2 object-group RDP
access-list itdev_access_in extended permit tcp object-group office_Developer_Workstations 98.136.48.0 255.255.255.0 object-group Yahooo_Messenger
access-list itdev_access_in extended permit icmp object-group DM_INLINE_NETWORK_9 host office_Monitor_Server echo-reply
access-list itdev_access_in extended permit tcp 192.168.200.0 255.255.255.0 object-group Rackspace_SMTP_Servers eq smtp
access-list systems_access_in extended permit object-group ActiveDirectoryAuth object-group office_AD_clients object-group office_AD_servers
access-list systems_access_in extended permit object-group WindowsShares object-group office_FS_clients object-group office_FS_servers
access-list systems_access_in extended permit object-group NetworkPrinting object-group office_Print_clients object-group office_Print_servers
access-list systems_access_in extended permit tcp object-group office_ITDev_WebServer_clients object-group office_ITDev_Web_servers object-group ITDev_Webserver_Ports
access-list systems_access_in extended permit tcp object-group office_Jabber_clients object-group office_Jabber_servers object-group Jabber
access-list systems_access_in extended permit tcp object-group office_JIRA_clients object-group office_Jabber_servers eq www
access-list systems_access_in extended permit tcp object-group office_Printer_WUI_clients object-group office_Print_servers eq www
access-list systems_access_in extended permit tcp object-group office_SysAdmin 192.168.150.0 255.255.255.0 object-group RDP
access-list systems_access_in extended permit tcp object-group office_SysAdmin 192.168.200.0 255.255.255.0 object-group RDP
access-list systems_access_in extended permit tcp object-group office_SysAdmin object-group office_AD_servers object-group RDP
access-list systems_access_in extended permit tcp object-group office_SysAdmin object-group office_FS_servers object-group RDP
access-list systems_access_in extended permit tcp object-group office_SysAdmin object-group office_JIRA_servers object-group RDP
access-list systems_access_in extended permit tcp object-group office_SysAdmin 192.168.200.0 255.255.255.0 eq ssh
access-list systems_access_in extended permit tcp object-group office_SysAdmin host DevDB eq sqlnet
access-list systems_access_in extended permit tcp object-group office_SysAdmin 192.168.100.0 255.255.255.0 object-group OMSA
access-list systems_access_in extended permit tcp object-group office_SysAdmin 192.168.200.0 255.255.255.0 object-group OMSA
access-list systems_access_in extended permit tcp object-group office_SysAdmin host switch eq https
access-list systems_access_in extended permit tcp object-group office_SysAdmin host server object-group RDP
access-list systems_access_in extended permit udp 192.168.250.0 255.255.255.0 object-group Outside_DNS eq domain
access-list systems_access_in extended permit tcp 192.168.250.0 255.255.255.0 any eq https
access-list systems_access_in extended permit tcp 192.168.250.0 255.255.255.0 any eq www
access-list systems_access_in extended permit object-group Communicator_Ports 192.168.250.0 255.255.255.0 host server
access-list systems_access_in extended permit udp 192.168.250.0 255.255.255.0 any eq isakmp
access-list systems_access_in extended permit udp 192.168.250.0 255.255.255.0 any eq 4500
access-list systems_access_in extended permit udp 192.168.250.0 255.255.255.0 any eq 10000
access-list systems_access_in extended permit tcp object-group office_SysAdmin object-group DM_INLINE_NETWORK_5 eq ssh
access-list systems_access_in extended permit tcp object-group office_SysAdmin object-group DM_INLINE_NETWORK_6 object-group RDP
access-list systems_access_in extended permit tcp object-group office_SysAdmin object-group DM_INLINE_NETWORK_7 object-group OMSA
access-list systems_access_in extended permit tcp object-group office_SysAdmin host IQ100 eq 8888
access-list systems_access_in extended permit tcp object-group office_SysAdmin host WEBDEV1 object-group DM_INLINE_TCP_1
access-list systems_access_in extended permit tcp object-group office_SysAdmin object-group prod_DBServers object-group OEM
access-list systems_access_in extended permit tcp object-group office_SysAdmin host 192.168.50.100 object-group DM_INLINE_TCP_2
access-list systems_access_in extended permit icmp object-group office_SysAdmin 192.158.50.0 255.255.255.0
access-list systems_access_in extended permit object-group Nagios_Office_Monitoring_Ports host office_Monitor_Server object-group DM_INLINE_NETWORK_12
access-list systems_access_in extended permit tcp host office_Monitor_Server object-group DM_INLINE_NETWORK_13 object-group Tomcat_TCP_Ports
access-list systems_access_in extended permit tcp object-group office_SysAdmin object-group DM_INLINE_NETWORK_16 object-group Tomcat_TCP_Ports
access-list systems_access_in extended permit tcp 192.168.250.0 255.255.255.0 object-group SMTP_Servers eq smtp
access-list systems_access_in extended permit tcp object-group office_SysAdmin host 192.168.0.1 eq https
access-list infrastructure_access_in extended permit udp 192.168.100.0 255.255.255.0 object-group Outside_DNS eq domain
access-list infrastructure_access_in extended permit icmp object-group DM_INLINE_NETWORK_14 host office_Monitor_Server echo-reply
access-list voip_access_in extended permit udp 192.168.125.0 255.255.255.0 object-group Outside_DNS eq domain
access-list voip_access_in extended permit tcp 192.168.125.0 255.255.255.0 any eq www
access-list voip_access_in extended permit tcp 192.168.125.0 255.255.255.0 any eq https
access-list voip_access_in extended permit udp 192.168.125.0 255.255.255.0 host 198.123.30.132 eq ntp
access-list infrastructure_nat0_outbound_1 extended permit ip 192.168.100.0 255.255.255.0 192.168.101.0 255.255.255.192
access-list infrastructure_nat0_outbound_1 extended permit ip 192.168.100.0 255.255.255.0 object-group DM_INLINE_NETWORK_18
access-list <split tunnel acl name> standard permit 192.168.125.0 255.255.255.0
access-list <split tunnel acl name> standard permit 192.168.100.0 255.255.255.0
access-list <split tunnel acl name> standard permit 192.168.200.0 255.255.255.0
access-list <split tunnel acl name> standard permit 192.168.250.0 255.255.255.0
access-list voip_nat0_outbound extended permit ip 192.168.125.0 255.255.255.0 192.168.101.0 255.255.255.192
access-list systems_nat0_outbound extended permit ip 192.168.250.0 255.255.255.0 192.168.101.0 255.255.255.192
access-list systems_nat0_outbound extended permit ip 192.168.250.0 255.255.255.0 object-group DM_INLINE_NETWORK_4
access-list infrastructure_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.101.0 255.255.255.192
access-list infrastructure_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 object-group DM_INLINE_NETWORK_17
access-list outside_1_cryptomap extended permit ip object-group DM_INLINE_NETWORK_1 object-group DM_INLINE_NETWORK_2
access-list voip_nat0_outbound_1 extended permit ip 192.168.125.0 255.255.255.0 192.168.101.0 255.255.255.192
access-list soa_nat0_outbound extended permit ip 192.168.150.0 255.255.255.0 192.168.101.0 255.255.255.192
access-list soa_nat0_outbound extended permit ip 192.168.150.0 255.255.255.0 object-group DM_INLINE_NETWORK_3
access-list itdev_nat0_outbound extended permit ip 192.168.200.0 255.255.255.0 192.168.101.0 255.255.255.192
access-list itdev_nat0_outbound extended permit ip 192.168.200.0 255.255.255.0 object-group DM_INLINE_NETWORK_2 
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
mtu dmz 1500
mtu infrastructure 1500
mtu voip 1500
mtu soa 1500
mtu itdev 1500
mtu systems 1500
mtu management 1500
ip local pool <pool name> 192.168.101.1-192.168.101.50 mask 255.255.255.0
no failover
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-634-53.bin
no asdm history enable
arp timeout 14400
nat-control
global (outside) 1 interface
nat (dmz) 1 192.158.50.0 255.255.255.0
nat (infrastructure) 0 access-list infrastructure_nat0_outbound_1
nat (infrastructure) 1 192.168.100.0 255.255.255.0
nat (voip) 0 access-list voip_nat0_outbound_1
nat (voip) 1 192.168.125.0 255.255.255.0
nat (soa) 0 access-list soa_nat0_outbound
nat (soa) 1 192.168.150.0 255.255.255.0
nat (itdev) 0 access-list itdev_nat0_outbound
nat (itdev) 1 192.168.200.0 255.255.255.0 tcp 100 0
nat (systems) 0 access-list systems_nat0_outbound
nat (systems) 1 192.168.250.0 255.255.255.0
static (voip,soa) 192.168.125.0 192.168.125.0 netmask 255.255.255.0
static (itdev,infrastructure) 192.168.200.0 192.168.200.0 netmask 255.255.255.0
static (itdev,voip) 192.168.200.0 192.168.200.0 netmask 255.255.255.0
static (soa,infrastructure) 192.168.100.0 192.168.150.0 netmask 255.255.255.0
static (infrastructure,itdev) 192.168.100.0 192.168.100.0 netmask 255.255.255.0
static (infrastructure,systems) 192.168.100.0 192.168.100.0 netmask 255.255.255.0
static (infrastructure,soa) 192.168.100.0 192.168.100.0 netmask 255.255.255.0
static (itdev,systems) 192.168.200.0 192.168.200.0 netmask 255.255.255.0
static (itdev,soa) 192.168.200.0 192.168.200.0 netmask 255.255.255.0
static (soa,voip) 192.168.150.0 192.168.150.0 netmask 255.255.255.0
static (soa,itdev) 192.168.150.0 192.168.150.0 netmask 255.255.255.0
static (soa,systems) 192.168.150.0 192.168.150.0 netmask 255.255.255.0
static (voip,itdev) 192.168.125.0 192.168.125.0 netmask 255.255.255.0
static (voip,systems) 192.168.125.0 192.168.125.0 netmask 255.255.255.0
static (dmz,systems) 192.158.50.0 192.158.50.0 netmask 255.255.255.0
static (systems,infrastructure) 192.168.250.0 192.168.250.0 netmask 255.255.255.0
static (systems,soa) 192.168.250.0 192.168.250.0 netmask 255.255.255.0
static (systems,itdev) 192.168.250.0 192.168.250.0 netmask 255.255.255.0
static (systems,voip) 192.168.250.0 192.168.250.0 netmask 255.255.255.0
static (systems,dmz) 192.168.250.0 192.168.250.0 netmask 255.255.255.0 
access-group outside_access_in in interface outside
access-group dmz_access_in in interface dmz
access-group infrastructure_access_in in interface infrastructure
access-group voip_access_in in interface voip
access-group soa_access_in in interface soa
access-group itdev_access_in in interface itdev
access-group systems_access_in in interface systems
route outside 0.0.0.0 0.0.0.0 <ip address> 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 192.168.251.0 255.255.255.0 management
http 192.168.250.0 255.255.255.0 systems
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 set pfs
crypto map outside_map 1 set peer 12.109.80.164
crypto map outside_map 1 set transform-set ESP-AES-256-SHA
crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 5
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
crypto isakmp policy 10
authentication pre-share
encryption des
hash sha
group 2
lifetime 86400
crypto isakmp policy 30
authentication pre-share
encryption aes-256
hash sha
group 5
lifetime 86400
no vpn-addr-assign aaa
no vpn-addr-assign dhcp
vpn-addr-assign local reuse-delay 5
telnet 192.168.250.0 255.255.255.0 systems
telnet timeout 5
ssh 192.168.250.0 255.255.255.0 systems
ssh timeout 5
console timeout 0
management-access management
dhcpd auto_config outside
!
dhcpd address 192.168.125.10-192.168.125.30 voip
dhcpd dns 68.15.28.11 68.105.29.12 interface voip
!
dhcpd address 192.168.150.10-192.168.150.30 soa
dhcpd dns 68.105.28.12 68.105.29.11 interface soa
dhcpd enable soa
!

threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
webvpn
anyconnect-essentials
group-policy <policy name>
group-policy <policy name> attributes
dns-server value <dns servers>
vpn-tunnel-protocol IPSec
split-tunnel-policy tunnelspecified
split-tunnel-network-list value <split tunnel acl name>
<Users>
tunnel-group DefaultRAGroup ipsec-attributes
pre-shared-key *****
tunnel-group <group name> type remote-access
tunnel-group <group name> general-attributes
address-pool <pool name>
default-group-policy <group name>
tunnel-group <group name> ipsec-attributes
pre-shared-key *****
tunnel-group <remote IP> type ipsec-l2l
tunnel-group <remote IP> ipsec-attributes
pre-shared-key *****
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
  message-length maximum 512
policy-map global_policy
class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny 
  inspect sunrpc
  inspect xdmcp
  inspect sip 
  inspect netbios
  inspect tftp
  inspect ip-options
!
service-policy global_policy global
prompt hostname context
call-home
profile CiscoTAC-1
  no active
  destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
  destination address email [email protected]
  destination transport-method http
  subscribe-to-alert-group diagnostic
  subscribe-to-alert-group environment
  subscribe-to-alert-group inventory periodic monthly
  subscribe-to-alert-group configuration periodic monthly
  subscribe-to-alert-group telemetry periodic daily
Cryptochecksum:46604574d5dd6acba3b8e879f7b92d73
: end

Correct Answer by Maykol Rojas about 6 years 9 months ago

Hello Daniel,


LOL, those kind of things happen, dont worry, we are here to help, would you mark this topic as solved?


Cheers.


Mike

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Maykol Rojas Sun, 11/14/2010 - 17:35
User Badges:
  • Cisco Employee,
  • Participante Destacado,

    Mejor Publicación, Diciembre del 2015

Hello Daniel,


When you say you cannot ping the gateway you mean you cannot ping 192.158.50.1 255.255.255.0? By default, you should be able to ping it. Can you check if you can ping the host from the firewall? If you do a show arp, can you see the DMZ host listed? Is there any kind of firewall enabled on that machine on the DMZ?


Let us know.


Mike

remitprosupport Sun, 11/14/2010 - 17:54
User Badges:

Thanks for the reply Mike...


The host in the DMZ has a statically assigned IP of 192.168.50.100, netmask 255.255.255.0. I cannot ping the gateway (192.168.50.1) from the host and the firewall cannot ping the host either.


Strangely, when I run "show arp", there's no entry for 192.168.50.100, but one for 169.254.12.98, which I think is the IP address windows automatically assigns when an interface can't get an IP from a DHCP server. That shouldn't have come from the host in the DMZ though, because it's always had a statically assigned IP...

Jennifer Halim Sun, 11/14/2010 - 17:38
User Badges:
  • Cisco Employee,

Your DMZ is assigned VLAN 50, and currently base on the configuration, you can:

1) Connect to ASA ethernet 0/1 directly, and give it IP address in the same subnet as VLAN 50 - 192.168.50.0/24, and you should be able to ping the DMZ interface 192.168.50.1


OR/


2) Currently ASA ethernet 0/2 is a trunk port, however, it's not allowing VLAN 50. If you are connecting your PC to switch port in VLAN 50, and trunk the switch to the ASA, then you would need to allow VLAN 50 to be trunked through on the ASA.

remitprosupport Sun, 11/14/2010 - 17:56
User Badges:

Thanks Jennifer...


The device is connected directly to the firewall port (0/1), and not on a switch port that uses the trunk. I did also try assigning the DMZ interface to a switchport that would use the trunk, and it made no difference. I've also placed a hub in between the host and the firewall port, also with no effect.

Jennifer Halim Sun, 11/14/2010 - 18:01
User Badges:
  • Cisco Employee,

You mention earlier that when you perform show arp, you were seeing entry for 169.254.12.98, is the MAC address for the 169.254.12.98 ARP entry the same as your PC MAC address? If it is, you should perform "clear arp" on the ASA.

Maykol Rojas Sun, 11/14/2010 - 18:21
User Badges:
  • Cisco Employee,
  • Participante Destacado,

    Mejor Publicación, Diciembre del 2015

Hello Daniel,


Jennifer is right, if you have the host directly connected with an IP address statically assign, try to clear the ARP and try to ping the host again.


Let us know the results.


Mike

remitprosupport Sun, 11/14/2010 - 18:34
User Badges:

Thanks both for the replies. After clearing the arp cache on the firewall, I still can't ping. The mystery arp entry hasn't returned, but I did confirm that the mac from the mystery entr does not match either nic on the dmz host.


I also tried switching over to the other nic with a different IP on the same network, and still no luck. Also, there are no new arp entries for the dmz network.

If you have any more ideas, they're greatly appreciated.

Jennifer Halim Sun, 11/14/2010 - 18:36
User Badges:
  • Cisco Employee,

Maybe cable issue? and have you also tried a different host? or even tried different IP Address? and just confirming that the netmask is 255.255.255.0?

remitprosupport Sun, 11/14/2010 - 18:44
User Badges:

I've tried different cables and giving the existing host a different IP, with no luck. I've moved this host to another network and it magically works again.


I've added a different host to the dmz and it also cannot ping. I've also moved the dmz to a different switchport on the firewall, also with no luck. I've verified the netmask on both the host and the firewall. Here's an interface detail for the dmz interface:



Interface Vlan50 "dmz", is up, line protocol is up
  Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec
    MAC address d0d0.fd45.64fa, MTU 1500
    IP address 192.158.50.1, subnet mask 255.255.255.0
  Traffic Statistics for "dmz":
    4837 packets input, 452091 bytes
    13 packets output, 448 bytes
    3009 packets dropped
      1 minute input rate 0 pkts/sec,  0 bytes/sec
      1 minute output rate 0 pkts/sec,  0 bytes/sec
      1 minute drop rate, 0 pkts/sec
      5 minute input rate 0 pkts/sec,  8 bytes/sec
      5 minute output rate 0 pkts/sec,  0 bytes/sec
      5 minute drop rate, 0 pkts/sec
remitprosupport Sun, 11/14/2010 - 18:54
User Badges:

Well guys, I have to say the problems been staring me in the face and I just now noticed it. And of the dozens of times I checked the interface config I didn't see it.


You'll notice that the IP address I have configured is 192.158.50.1, and it should be 192.168.50.1.


Sorry for the time spent working with me on this. I really do appreciate your help.


Thanks,


Dan

Jennifer Halim Sun, 11/14/2010 - 18:57
User Badges:
  • Cisco Employee,

Ooopss, the famous typo, I should have noticed too earlier

Correct Answer
Maykol Rojas Sun, 11/14/2010 - 18:57
User Badges:
  • Cisco Employee,
  • Participante Destacado,

    Mejor Publicación, Diciembre del 2015

Hello Daniel,


LOL, those kind of things happen, dont worry, we are here to help, would you mark this topic as solved?


Cheers.


Mike

Jennifer Halim Sun, 11/14/2010 - 18:54
User Badges:
  • Cisco Employee,

Weird.. looks like lots of packets are dropped.

Try to test with packet tracer and see where it says it's failing, and last resort, try to reload the ASA.

Actions

This Discussion

Related Content