PIX515A to PIX515B, IPSEC tunnel. I can ping from inside subnet A to inside subnet B. I can ping from PIXA at CLI to inside subnet B. However, I can't ping from PIXB CLI to inside A. This doesn't make sense. As stated, I can ping from anywhere in subnet B to inside subnet A, just not from PIXB CLI.
My configs are quite large so I haven't posted them. I can, but I was hoping for some hints as where to look as this must be a common problem.
I thought a bit more deeply about the config after reading your reply. There were two NONAT entries on PIXB that were no longer needed that pointed to an old internal LAN subnet. I hadn't removed these from the NONAT list when I redesigned the LAN. I just didn't think that they would cause any issue. What I learned: NONAT rules must be mirrors of each other on the ipsec tunnel endpoints for the PIX firewalls.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...