pings from ASA or ASA

Unanswered Question
Jan 15th, 2007
User Badges:

Hi,


I have a site-to-site VPN between an ASA 5505 and a PIX 501. The tunnel connects to private LANs A and B.

Now from LAN A I can ping hosts on LAN B.

From ASA on LAN A can ping hosts on LAN A.

But I can't ping from ASA on A hosts behind PIX on remote LAN B. And vice versa from PIX on LAN B it is not possible to ping hosts on LAN A.

I can successfully ping Internet addresses from both ASA and PIX.

ICMP is allowed on both ASA and PIX.

Should specifically allow ICMP for the tunnel? What else might I miss?


Thank you.

Regards,

Alex

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
ccna2 Mon, 01/15/2007 - 02:20
User Badges:

Hi,


You need to issue the command: "management-access inside" in order for this to work.


Regards,


Thomas BJ.

augnevenok Mon, 01/15/2007 - 13:59
User Badges:

"management-access inside" is enabled on both devices. Still cannot ping from device hosts that are behind the other device across VPN tunnel.

What should be enabled/allowed for these pings to come through?


Thank you very much.

Regards,

Alex


ccna2 Mon, 01/15/2007 - 23:38
User Badges:

Hi Alex,


On each Firewall is the inside interface IP address included in the access-list specifying the interesting traffic?


Do you have filters configured?


Are you correctly using the ping command: "ping inside x.x.x.x"?


Regards,


Thomas BJ

Actions

This Discussion