Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Site-to-Site VPN - Can't ping remote subnet

Hi all.

I have a site-to-site IPSEC VPN running between a 5510(HQ) and 5505(Remote). All is working on the tunnel. Crypto maps and ACLs are symmetrical. I see the tunnel is up for the required subnets. However I cannot ping from internal subnets inside 5510 to remote LAN inside 5505 and vice-versa. I have other VPN spokes to 5510 where I can ping inside x.x.x.x from remote LAN with success. Can figure out what I am missing. I can ping internet items but cannot ping HQ.

Any suggestions?

Also I am a now learning the ASAs so I am not an expert.  I do know that I am allowing ICMP from outside. Both my NONAT statement and crypto map are running off same object group that lists the HQ subnets.

Thanks in advance.

1 ACCEPTED SOLUTION

Accepted Solutions

Re: Site-to-Site VPN - Can't ping remote subnet

The 5505 is missing the command:

management-access inside

Federico.

4 REPLIES

Re: Site-to-Site VPN - Can't ping remote subnet

Hi,

Enable on both sides access to the inside interface via VPN with the command:

management access-inside

Then, try to PING from the ASA to the other's ASA inside IP address, like this:

ping inside x.x.x.x

If it works, then check the internal subnet has a route pointing to the ASA for the interesting traffic.

Federico.

New Member

Re: Site-to-Site VPN - Can't ping remote subnet

Also to add....I can ping all 5510 inside subnets from clients on the 5505 LAN. Just cant from the 5505 itself via the ping inside x.x.x.x command.

I also can't ping the remote 5505 LAN from anywhere inside the 5510. 

Makes sense?

Re: Site-to-Site VPN - Can't ping remote subnet

The 5505 is missing the command:

management-access inside

Federico.

New Member

Re: Site-to-Site VPN - Can't ping remote subnet

You the man Federico!

Thanks for the quick reply!

That worked!!!

1907
Views
0
Helpful
4
Replies