Alright this one has stumped me for sure and I think I have looked at it for so long I have gotten tunnel vision. I have a site to site vpn between a pix and an ASA. The tunnel works completely fine, but I can't ping across the tunnel. I have conducted multiple experiments and the problem appears to be on the host side.
Host ASA = 8.0.2 ... 192.168.1.253
Host Router 12.4. ... 192.168.1.254
Remote Pix 6.3.5
Remote Client 5.001
Here are the ICMP debugs
Site to Site .... Host 192.168.60.235 ping to 192.168.1.254
Host ASA
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=33281 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=33537 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=33793 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=34049 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=34305 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=34561 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=34817 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=35073 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=35329 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=35585 len=32
Host Internal router
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
Remote Access ... host 192.168.253.17 ping to 192.168.1.254
ASA
ICMP echo request from outside:192.168.253.17 to inside:192.168.1.254 ID=1792 seq=10496 len=32
ICMP echo reply from inside:192.168.1.254 to outside:192.168.253.17 ID=1792 seq=10496 len=32
ICMP echo request from outside:192.168.253.17 to inside:192.168.1.254 ID=1792 seq=10752 len=32
ICMP echo reply from inside:192.168.1.254 to outside:192.168.253.17 ID=1792 seq=10752 len=32
ICMP echo request from outside:192.168.253.17 to inside:192.168.1.254 ID=1792 seq=11008 len=32
ICMP echo reply from inside:192.168.1.254 to outside:192.168.253.17 ID=1792 seq=11008 len=32
ICMP echo request from outside:192.168.253.17 to inside:192.168.1.254 ID=1792 seq=11264 len=32
ICMP echo reply from inside:192.168.1.254 to outside:192.168.253.17 ID=1792 seq=11264 len=32
Router
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.253.17
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.253.17
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.253.17
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.253.17
So basically it works perfect from the remote client but not from the remote site. Like I said I have full connectivity from 192.168.60.x to 192.168.1.x ... I just cant seem to get icmp from 192.168.1.254 back to the ASA which is 192.168.1.253.
Host ASA = 8.0.2 ... 192.168.1.253
Host Router 12.4. ... 192.168.1.254
Remote Pix 6.3.5
Remote Client 5.001
Here are the ICMP debugs
Site to Site .... Host 192.168.60.235 ping to 192.168.1.254
Host ASA
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=33281 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=33537 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=33793 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=34049 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=34305 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=34561 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=34817 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=35073 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=35329 len=32
ICMP echo request from outside:192.168.60.235 to inside:192.168.1.254 ID=512 seq=35585 len=32
Host Internal router
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.60.235
Remote Access ... host 192.168.253.17 ping to 192.168.1.254
ASA
ICMP echo request from outside:192.168.253.17 to inside:192.168.1.254 ID=1792 seq=10496 len=32
ICMP echo reply from inside:192.168.1.254 to outside:192.168.253.17 ID=1792 seq=10496 len=32
ICMP echo request from outside:192.168.253.17 to inside:192.168.1.254 ID=1792 seq=10752 len=32
ICMP echo reply from inside:192.168.1.254 to outside:192.168.253.17 ID=1792 seq=10752 len=32
ICMP echo request from outside:192.168.253.17 to inside:192.168.1.254 ID=1792 seq=11008 len=32
ICMP echo reply from inside:192.168.1.254 to outside:192.168.253.17 ID=1792 seq=11008 len=32
ICMP echo request from outside:192.168.253.17 to inside:192.168.1.254 ID=1792 seq=11264 len=32
ICMP echo reply from inside:192.168.1.254 to outside:192.168.253.17 ID=1792 seq=11264 len=32
Router
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.253.17
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.253.17
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.253.17
1w3d: ICMP: echo reply sent, src 192.168.1.254, dst 192.168.253.17
So basically it works perfect from the remote client but not from the remote site. Like I said I have full connectivity from 192.168.60.x to 192.168.1.x ... I just cant seem to get icmp from 192.168.1.254 back to the ASA which is 192.168.1.253.