Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

asa5510 block ping

Status
Not open for further replies.

charliemao

IS-IT--Management
Aug 9, 2008
12
CN
my question is I use cisco asa5510 as a firewall beteween inside lan and internet. I use NAT to make client go internet. it's find. but I can't ping outside address(internet address), because sometimes I need to ping outside address to test whether it can be reached. I also use icmp permit any inside/outside, but still don't work.
thanks for any help
 
post a scrubbed config (take out passwords and mask the middle 2 octets of public ips) and we'll have a look.

Brent
Systems Engineer / Consultant
CCNP, CCSP
 
I second that i cant get pings to go through, but i dont even have internet coming through yet...
 
Are you trying to ping the outside interface of the firewall? If so you are going to need to ICMP command.

netleets(config)# icmp permit host 192.168.1.10 outide

If you are trying to ping through the firewall, in some versions of code, Cisco does not include ICMP in the "IP" acls and require a separate acl entry specifically for ICMP.

If neither of the 2 above senerios are applicable, please paste a scrubbed version of your config.

IT Security news and information
In plain English
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top