05-21-2007 04:41 AM - edited 03-11-2019 03:17 AM
Hi all.
This is my first setup of a Cisco ASA box.
I'm having a lot of problems with use of static route
If I make a PING from the ASA box, I get a replay.
But if the ping comes from a computer, I keep getting: Deny inbound icmp src inside:XXX des inside:YYY (Type 8, code 0)
I have tried to make a NAT rule for this, but I cannot make a role src inside, drs inside
Can any one help me whit this?
Thanks?
Best regards.
Stig B.
05-22-2007 05:53 AM
srue, he is trying to hairpin inside, not pat to the outside.
mnetworks,
Mind if we try something else?
no global (LAN) 200 interface
access-list LAN_nat0_outbound extended permit ip any 192.168.168.0 255.255.255.0
Then try to ping something on 192.168.168.0.
05-22-2007 06:38 AM
Sorry, no connection.
The log says:
6|May 22 2007 16:40:41|302021: Teardown ICMP connection for faddr 192.168.163.11/512 gaddr 192.168.168.12/0 laddr 192.168.168.12/0
On a computer, on the 192.168.168.x network I can ping 192.168.163.1
Thanks...
05-22-2007 06:45 AM
Yes, you can ping from 192.168.168 to 192.168.163 because it is not being routed through the ASA. Maybe the problem is the return traffic from 192.168.168.12 must be routed back to inside of ASA. As it stands now, the return traffic from the ping would not, it would be routed directly from 192.168.163.30 to 192.168.163.11. Maybe try to add a static route on 163.30 like this.
ip route 192.168.163.11 255.255.255.255 192.168.163.1
This would force the return traffic to inside of ASA.
05-22-2007 07:08 AM
Another way to force traffic to the ASA would be to nat the traffic 192.168.163.x to 192.168.168.x like this.
access-list nat_to_168 extended permit ip 192.168.163.0 255.255.255.0 192.168.168.0 255.255.255.0
global (inside) 20 interface
nat (inside) 20 access-list nat_to_168
05-23-2007 09:59 AM
Have you had any luck with this?
05-23-2007 10:05 AM
what kind of device is 192.168.163.30? is this a router? multi layer switch?
05-23-2007 10:06 AM
Router
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide