Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

ASA 5505 TFTP

i have a new asa 5505 and i am wanting to update the asdm and asa and I am able to ping the inside address, but i am not able to ping my tftp server when it is getting the ip from the asa.

17 REPLIES
Hall of Fame Super Blue

Re: ASA 5505 TFTP

Hi

Is the tftp server on the same subnet as the inside interface of the ASA ?. If not does the ASA have a route to the tftp server subnet ?

Jon

Community Member

Re: ASA 5505 TFTP

the tftp server is getting a dhcp ip from the ASA. when i try and ping from the inside to that Ip it is not being found. to answer your question, yes the subnet's are the same.

Community Member

Re: ASA 5505 TFTP

Put this in the ASA and let me know if you can ping

icmp permit any inside

Community Member

Re: ASA 5505 TFTP

I entered that command. I am still unable to ping my 192.168.1.2 TFTP server

Community Member

Re: ASA 5505 TFTP

Can you post your ASA config?

Community Member

Re: ASA 5505 TFTP

attached is our latest config

Community Member

Re: ASA 5505 TFTP

Try remove the management-only from vlan 1

interface Vlan1

no management-only

Community Member

Re: ASA 5505 TFTP

It has been done and I am still not able to ping from the inside interface to my TFTP server

Community Member

Re: ASA 5505 TFTP

I just notice that in your config there is no Ethernet interface assign to vlan1 that is your inside

Community Member

Re: ASA 5505 TFTP

by default all my ethernet interfaces are part of VLAN 1, it just doesn't show up in the config. If I go in to the asdm, under interfaces i see that all are joined to VLAN 1.

Community Member

Re: ASA 5505 TFTP

The TFTP server is connected in the ASA?

Community Member

Re: ASA 5505 TFTP

yes, tftp server is plugged into ethernet 0/1

Community Member

Re: ASA 5505 TFTP

Did you copy the config from another pix/asa dumped in this asa?

There is no ip in the outside interface, there is an IPSec tunnel, multiple telnet, http and ssh hosts in outside and then an ssh any outside. There is no acl apply in the inside but there is an acl apply to the outside allowing anything.

Try this, if doesn't then try erasing the config and start over.

access-list inside_access_in extended permit ip any any

access-group inside_access_in in interface inside

Community Member

Re: ASA 5505 TFTP

I dumped everything from the other asa from the start. I took off the outside IP since this will be using a different static IP. The other asa is working fine, but this asa is not allowing the ping from inside to any of the ethernet interfaces. I am leaning towards erasing and starting over from stratch.

Community Member

Re: ASA 5505 TFTP

i set the ASA back to the factory default and loaded everything from the ASA that was working. I am able to get out to the internet, but still not able to ping hosts from the inside interface. On the other ASA I am able to ping and I am using the same config. Any ideas before I open a TAC case.

Community Member

Re: ASA 5505 TFTP

Did you change the ip configuration in the config before you loaded?

Community Member

Re: ASA 5505 TFTP

No, just reloaded the ASA and then copied the config through hyper terminal once it finished.

1232
Views
4
Helpful
17
Replies
CreatePlease to create content