cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
18547
Views
0
Helpful
3
Replies

loopback interface in ASA or FWSM

snarayanaraju
Level 4
Level 4

Hi experts,

Is it possible to create loopback interfaces in FWSM or ASA firewall

The need is i want a interface command to the firewall as I am facing problem in pinging one interface IP ADDRESS from the other zones.

Thanks in advance

sairam

3 Replies 3

Kevin Redmon
Cisco Employee
Cisco Employee

Sairam,

No - Cisco firewalls do NOT allow for a loopback address. If you are having issues with pinging a certain interface IP address, please be sure that you are pinging the interface closest to the client machine - ie NOT another interface. Unlike a router, the Cisco firewalls do NOT allow you to ping a "far-side" interface. Also, be sure that you have 'icmp permit ' for the relevant interface.

Not entirely true. You can issue the 'management-access inside' command, which will enable you to SSH and issue ping/snmp commands on the inside interface IP eg. from the far-end of a IPsec tunnel configured.

"Also, be sure that you have 'icmp permit ' for the relevant interface"

This is NOT true. Pix/ASA, by default, will let you ping the interface, unless explicitly dennied.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card