I have 2 interfaces on a ASA 5020. One external and one internal. External is on a C mask and internal is on a \23 mask.
I am inside another firewall so I have NAT setup and I have any to any between the interfaces.
Each interface talks to its side of the network but it seems that the 2 interfaces are not talking to each other. I can ping to each side with no problem with the correct interface but if I use the interface interface to ping out it doesn't work and the same with using the prod interface with pinging internally.
If your problem is that you can not PING a remote interface then that is by design and can not be made to work with any configuration.
What I specifically mean is that you can only PING the interface behind which you are located. If your host is behind "inside" interface it can PING the "inside" interface IP address but not the "outside" interface IP address. To be able to PING the "outside" interface IP address the host must be in a subnet that is located/found behind the "outside" interface.
You could run a packet tracer and see what that shows. Enter the following command by adding the relavent interface name for the ingress interface where the server is connected to, and the server's private IP.
The output should give you an idea if there is a drop for the traffic passing through your ASA...or not. And it should give us an idea where to start looking if there is a drop. If you want help looking at the output, please post the full output here (remove any public IPs).
Please remember to select a correct answer and rate helpful posts
Please remember to rate and select a correct answer
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...