08-21-2009 10:27 PM - edited 03-11-2019 09:08 AM
Hi experts,
Is it possible to create loopback interfaces in FWSM or ASA firewall
The need is i want a interface command to the firewall as I am facing problem in pinging one interface IP ADDRESS from the other zones.
Thanks in advance
sairam
08-23-2009 06:21 AM
Sairam,
No - Cisco firewalls do NOT allow for a loopback address. If you are having issues with pinging a certain interface IP address, please be sure that you are pinging the interface closest to the client machine - ie NOT another interface. Unlike a router, the Cisco firewalls do NOT allow you to ping a "far-side" interface. Also, be sure that you have 'icmp permit
10-24-2009 03:03 AM
Not entirely true. You can issue the 'management-access inside' command, which will enable you to SSH and issue ping/snmp commands on the inside interface IP eg. from the far-end of a IPsec tunnel configured.
10-24-2009 03:16 PM
"Also, be sure that you have 'icmp permit
This is NOT true. Pix/ASA, by default, will let you ping the interface, unless explicitly dennied.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: