pings from ASA or ASA

Unanswered Question
Jan 15th, 2007
User Badges:


I have a site-to-site VPN between an ASA 5505 and a PIX 501. The tunnel connects to private LANs A and B.

Now from LAN A I can ping hosts on LAN B.

From ASA on LAN A can ping hosts on LAN A.

But I can't ping from ASA on A hosts behind PIX on remote LAN B. And vice versa from PIX on LAN B it is not possible to ping hosts on LAN A.

I can successfully ping Internet addresses from both ASA and PIX.

ICMP is allowed on both ASA and PIX.

Should specifically allow ICMP for the tunnel? What else might I miss?

Thank you.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
ccna2 Mon, 01/15/2007 - 02:20
User Badges:


You need to issue the command: "management-access inside" in order for this to work.


Thomas BJ.

augnevenok Mon, 01/15/2007 - 13:59
User Badges:

"management-access inside" is enabled on both devices. Still cannot ping from device hosts that are behind the other device across VPN tunnel.

What should be enabled/allowed for these pings to come through?

Thank you very much.



ccna2 Mon, 01/15/2007 - 23:38
User Badges:

Hi Alex,

On each Firewall is the inside interface IP address included in the access-list specifying the interesting traffic?

Do you have filters configured?

Are you correctly using the ping command: "ping inside x.x.x.x"?


Thomas BJ


This Discussion