ASA5540 - no ICMP response from inside subinterface

Hello guys,.

I need to monitor ping inside subinterface my ASA5540, is - it possible?

I get no replys but ICMP requests, out of the box.

I need to ping to the 192.168.10.250 of the 192.168.5.55:

ASA Version 8.0 (5)

interface GigabitEthernet0/1

nameif inside

security-level 100

IP 192.168.30.50 255.255.255.0

!

interface GigabitEthernet0/1.1

Description of voting

No vlan

No nameif

security-level 100

IP 192.168.10.250 255.255.255.0

permit access list extended ip host 192.168.10.250 inside_nat0_outbound 192.168.5.55

inside_access_in access list extended icmp permitted any any debug log

ICMP allow any inside

Thank you guys!

Hello

You cannot ping an ASA interface behind another interface.

One exception to this rule is for connections from a VPN connection. Then, you can use the command "access management" to enable the ICMP connections and management of an ASA interface behind another interface.

So I don't think you can get this to work.

The host of the poll with ICMP must be behind the interface being queried.

Although I suppose that the method for monitoring all interfaces on the SAA would use SNMP.

-Jouni

Tags: Cisco Security

Similar Questions

  • WRT160NL WAN ICMP responses

    Hello, I just bought a WRT160NL and im noticing that my WAN ip's ping'able is possible to disable ICMP responses on the WAN interface.

    Thank you!

    Hmmm...  Are you ping command from a device on the local network / wireless or in fact of the Internet / WAN side?

    I tried rattling from the outside and the setting works correctly as described.

    Ping from the inside always gets responses regardless of the setting.

  • No Ping response from Site to Site connection between 876 of Cisco and CheckPoint Firewall

    Hello!

    We try to create a Site-to-Site - connection IPSec between a Cisco 876 (local site) and a control-firewall station (remote site). Cisco 876 is not directly connected to the internet, but it is behind a router ADSL with port-forwarding, redirection of ports 500 and 4500. The configuration of the Cisco 876 running is attached to this thread. Unfortunately, I get no results when debugging the connection with the command "debug crypto isakmp" and "debug crypto ipsec".

    From the point of view of Checkpoint firewall the connection seems to be implemented, but there is no response from ping.

    The server in the local site to be achieved since the network behind the firewall Checkpoint has a routing entry "PEI route add [inside the ip-net Remote] 255.255.255.0 [inside the premises of intellectual property]" (see also annex current config name ip addresses).

    Establishing a VPN Cisco Client connection to the same router Cisco 876 works very well.

    Any help would be much appreciated!

    Jakob J. Blaette

    Hi Jakob,

    Add my two cents here.

    You should always verify that the following ports and Protocol are open:

    1 - UDP port 500--> ISAKMP

    2 - UDP port 4500--> NAT - T

    3-protocol 50---> ESP

    A LAN-to-LAN tunnel will never establish a TCP session, but it could use NAT - T (if behind a NAT). Remember that a single translation isn't a port forwarding, a LAN-to-LAN tunnel is not good unless you have a one-to-one translation of the NATted device, which I think, in your case the router is working.

    HTH.

    Portu.

    Please note all useful messages and mark this message as a response.

  • error message when try to sync the iPhone, "invalid response from the device?

    What can I do when I receive this error message when you try to sync to my iPhone 5 s - "invalid response from the device?

    -What are your 5 updating to 10.0.2 iOS iPhone? If this is the case, you must have the latest version of iTunes on your computer, which is required for Mac OS X 10.9.5 12.5.1, or above. To meet these specifications will be receiving this error.

  • Cannot connect iPhone 7 more to iTunes because an invalid response from the device

    I tried to sync my phone to iTunes and I get an error message stating "invalid response from the device. I tried to remove the password, and it still doesn't work. I also tried using a new USB cord. I'm doing something wrong? I can't sync my music or ringtones. Will there be an update to iOS 10 soon to solve this problem? I am extremely disappointed that I can not connect my new phone!

    You use iTunes version 12.5?

    Get the latest version of iTunes - Apple Support

  • make a clicking sound from inside my Mac

    Just started today. Every few minutes I get a clicking sound from inside my iMac. It seems to work ok, however. Thought, it may be overheating and cleaned by vacuuming all the vents, but it did not help.

    Perhaps an early indication of a hard drive failing. Support everything up immediately (if you have not already) and get it checked with a free diagnosis in an Apple Center.

  • No Satellite Pro 6100 no response from the screen

    Can anyone help?

    My 6100 Pro Satellite lit last night then automatically went into hibernation, despite being connected. Now when I turn it on there is no response from the screen, but if I plug a monitor to the laptop, the screen works (as long as I start in safe mode)

    Can anyone help?

    Hi Simon

    Disconnect all cables from the laptop and remove the battery.
    Wait a moment more (20 min) and reconnect the battery and the AC adapter.
    Then check if the laptop turns on and if the display works fine

    Good luck

  • An error has occurred has not got a response from the software update server (update.local). What should I do to update my laptop?

    An error has occurred has not got a response from the software update server (update.local). What should I do to update my laptop?

    It is one of the many problems that occur on my mac.

    Update of OS X El Capitan 10.11.4?

    1. backup Mac.

    2. install 10.11.4 combo update.

    https://support.Apple.com/kb/DL1869?viewlocale=en_US & local = en_US

  • NB200-h-13 - no response from the DNS server and gateway

    Hello

    I have netbook NB200-h-13 with XP SP3. Its impossible to connect to wireless internet and the error messages are
    HE DIDN'T THERE WAS NO RESPONSE FROM THE DNS SERVER
    HE DIDN'T THERE WAS NO RESPONSE FROM THE DEFAULT GATEWAY

    The connection with the ethernet cable is ok with the adpter reltek that also adpter atheros ar9285 WiFi is activation, working properly and the modem router signal is strong.

    Hi abk55,

    What program you receive this error message?
    Have you tried another browser, for example Firefox or Opera?

    I guess it has something to do with your wireless network card or WLAN parameters if the LAN cable is working properly. So you should try to update the WLAN driver on the Toshiba site.
    Also, try to disable the filtering of MAC addresses and use another encryption.

  • No response from the keyboard on Equium M40X

    Hi all

    Posted before on this problem, just mounted a new keyboard, but getting no response from it, the luminous numbers lock is on, but nothing works, it is a new keyboard, my old one was doing the same thing, reinstalled the system using a usb keyboard but still the same, no response from the keyboard, any ideas?

    Hello

    Connect the flat keyboard cable properly to the motherboard?
    Make sure that the keyboard cable is firmly connected to the system board.
    If the internal keyboard has been correctly connected, so I think there must be something wrong on the motherboard.

    I think detailed diagnosis can be done by a technician with experience much more as a common user like you and me.

  • Satellite Pro P100: Wlan with no response from the server proxy C-27

    I have a laptop model Satellete Pro P100 and tries to connect to a wireless router.
    I was able to connect to it over the past four months.

    Last week, I connected to a wired network and now he refuses to re - connect to my home wireless network. He acknowledges that I am connected but connectivity doctor says "there is no response from the server proxy (c-27).

    A friend in the House is able to connect to the internet with their computer without problem.
    I have tried everything I know, but need help please. Thank you

    Hello

    Have you checked in the properties of Wlan settings and the TCP/IP properties?
    Please check if the options: IP automatically get an address and get server address DNS are automatically set correctly.

  • Is it supposed to be a rattle from inside the phone?

    Got a Defy a few weeks ago. Love it until yesterday when I suddenly cant' hear someone on a phone call and only the speaker/headphone works (like make a few posts down). Back to T-mobile tomorrow.

    However, my phone has a deaf/rattle sound from inside the phone when you shake it, and you can feel something moving inside. I thought it was something to do with sensors/accelerometers in the phone or something, but now the internal speaker is broken I wonder if it is supposed to do this or if she actually always a hardware problem.

    Phone of someone else than the same noise/do the same thing? Is it supposed to do this or not?

    -Daniel

    There should not be a rattle... but there is!

    I have the same problem. It is caused by the battery move when you shake the phone, it doesn't have a tight fit. I used a piece of foam under the battery very thin to stop this rattle noise. Not impressed!

    You will see on these forums that some users have had problems with defective headphones... so far I did not have this.

    Hope that such Defys won't suffer from bad workmanship I really like the phone.

    Check your battery by shaking the phone with the cover off... let me know how you go.

  • Mailbox unavailable. The response from the server is: 5.7.1 error: content rejected

    I have an application that sends emails when running. Off late a user when he tries to send a mail it receives the following error message...

    "System.Net.Mail.SmtpException: unavailable mailbox." "The response from the server is: 5.7.1 error: content rejected '...

    Note that this happens when he tries to send mail to itself and not otherwise. Can someone here on which could mean the error? Thanks in advance... :))

    Error code is generated in the back-end.

    'System.Net.Mail.

    to System.Net.Mail.

    to System.Net.Mail.

    to System.Net.Mail.

    to System.Net.ClosableStream.

    to System.Net.Mail.MailWriter.

    to System.Net.Mail.SmtpClient.

    Hi guys,.

    Thanks for the reply!

    I contacted my sources by taking care of the servers and realized that the user was an id in which the address of the server was not set up with our servers in domain. He used to connect to our servers using the VPN client. This is why he could not send mails to id field not (in this case itself).

  • Move data directly from inside the loop

    Is it possible to move data directly from inside a loop outside the structure of matter in real time? I would like a chart of the data in a structure of matter in real time outside the structure of the case. Ideally, it would include information of the real deal and then the waiting period as a '0' for false case. Attached is a version simplified VI I'm working. I tried the local variables, but they only read the first item for loop puts each cycle T/F. One idea is welcome including a complete change in the structure of the VI.

    Thank you!


  • Is it possible to include 'Response from Microsoft' in my home screen "Windows Live"?

    Is it possible to include 'Response from Microsoft' in my home screen "Windows Live"?

    Post Windows Live questions in the appropriate forum found here:
    http://windowslivehelp.com/

Maybe you are looking for