Cisco ASA 5505 Firewall Logo

Related Topics:

Posted on Mar 01, 2011

I have configured Cisco ASA Firewall and I have given ICMP Inspect also But I cant able to ping the PC Kept in the DMZ from the Outside interface

1 Answer

Melvin Peter

Level 1:

An expert who has achieved level 1.

MVP:

An expert that got 5 achievements.

Governor:

An expert whose answer got voted for 20 times.

New Friend:

An expert that has 1 follower.

  • Contributor 30 Answers
  • Posted on Mar 01, 2011
Melvin Peter
Contributor
Level 1:

An expert who has achieved level 1.

MVP:

An expert that got 5 achievements.

Governor:

An expert whose answer got voted for 20 times.

New Friend:

An expert that has 1 follower.

Joined: Jun 30, 2010
Answers
30
Questions
1
Helped
29084
Points
63

HI,


· Please check the whether the security level for DMZ and outside interface, If DMZ is high security level. Please do the NAT configuration
· If it's having the same security level. Please issue the command "same-security-traffic permit inter-interface "in the global config mode.

Add Your Answer

×

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

0helpful
1answer

I have configured Cisco ASA Firewall and I have given ICMP Inspect also But I cant able to ping the PC Kept in the DMZ from the Outside interface

HI,


  • · Please check the whether the security level for DMZ and outside interface, If DMZ is high security level. Please do the NAT configuration
  • · If it's having the same security level. Please issue the command "same-security-traffic permit inter-interface "in the global config mode.
3helpful
2answers

Replacing a PIX 515E with an ASA 5510

Best way to migrate is to take the configuration of the old PIX and TFTP it to a PC or other server for safe keeping.

Then boot up the ASA in a lab environment and TFTP the configuration to the new unit and reboot. There will be some commands that don't translate correctly, but you can compare the configurations to each other to make sure all the access lists and NAT statements get transferred across.

Keep in mind that the PIX and the ASA name their interfaces differently, so there may be errors when you transfer the configuration. You can edit the configuration offline with something like Notepad and change the names of the interfaces to have it work.

Good luck!
0helpful
1answer

How to counfugre asa 5505 cisco Router

Use the Cisco ASDM or SDM software, that will give you an easy graphical interface to configure the ASA. One of them would have been shipped with the device.

Don't forget the ASA has to pre-configured, just a simple config. Have HTTPS enabled and telnet/SSH helps as well if you dont have a serial port or the console cable.

Cisco's website will give you quite a lot of info for free...
0helpful
1answer

I have a problem in asa5510 eth0 ip is 192.168.100.51 (inside) eth3 is static ip i can ping 4.2.2.4 from asa but i cant ping 4.2.2.4 from inside please solve this problems

It sounds like you have not allowed ICMP (ping) through the firewall, and you may need to put an access list in to allow this.
0helpful
1answer

Cisco ASA 5505 Firewall

1. Change your PCs default gateway to your firewalls' internal IP

2. configure the nameservers on your ASA

Then internet will work fine.
0helpful
1answer

Ploblems with dmz-outside (webpage). pix

Remove this line:

static (DMZ,INSIDE) 10.10.0.0 10.10.0.0 netmask 255.255.255.0

You don't need a translation going from a lower security level to a higher one. You will also need a nat line for the dmz so that pc's on the dmz will be translated outbound. The only connection that will work on the dmz is the webserver when he's sending traffic outbound with a source port of 80. Something like:

nat (DMZ) 101 10.10.0.0 255.255.255.0

Other than that, it looks like it should be working. You've got permission, a route, and a translation. Maybe "clear local-host 10.10.0.2" to get rid of any bad xlates and try again. Check debg level syslogs, run packet captures, "clear asp drop" then "show asp drop" after an attempt?

1helpful
1answer

ASA-5505 IOS 8.0(4)

Check for an IP conflict. How are you assigning the IP address on the workstations? If one of them happened to have the same ip address as the ip on the vlan1 on the ASA for example, you would have that exact issue.

Let me know how things go.
0helpful
1answer

CIsco ASA 5510 fire wall problem

Hi Thangaraj_j,

Can you provide the topology of your setup? Can you provide also the following:

- running configuration of the ASA
- ip address of the server (what kind of server is this? what tcp/udp port does it use)
- show xlate
- show con
- show log

Just a quick try, have you tried clearing the translation and the arp table?

commands to do it:

clear xlate
clear arp
clear local

Let me know and if it still doesn't work, try to ping the server from the pc clients and see if ping does work. (you need to allow icmp to pass thru in case you are denying it for testing purposes) Just send me the additional information given above.


Regards,

ex_ocsic_cat
9helpful
4answers

Installation of cisco asa 5510 firewall

If you can't get the manament working initially I suggest the following

Setup a console connection
Type "enable" and press enter to access priveleged exec mode on the ASA
Type "config terminal" and press enter to access configuration mode
Type "configure factory-default" and press enter to load default settings.
Assign a static IP to your PC of 192.168.1.5 and try to browse to https://192.168.1.1 (PC is plugged into management interface)

You should be prompted to begin using ASDM
Not finding what you are looking for?

194 views

Ask a Question

Usually answered in minutes!

Top Cisco Computers & Internet Experts

Brad Brown

Level 3 Expert

19187 Answers

Grand Canyon Tech
Grand Canyon Tech

Level 3 Expert

3867 Answers

Sean Wright
Sean Wright

Level 3 Expert

2045 Answers

Are you a Cisco Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...