ASA not allowing ping to distant or far interface IP

When i try to ping from inside lan to firewall DMZ interface IP it is not pingable and but from inside users i am able to ping firewall inside interface IP address.
I have following scenario where i am trying to ping from PC to ASA interface not pinging but i can ping so why ASA not allowing to ping distant interfaces?

You cannot ping the far interfaces by design. There is nothing you can do to change that behavior, this is done as a security measure by the ASA ( Built-in feature).

The adaptive security appliance only responds to ICMP traffic sent to the interface that traffic comes in on; you cannot send ICMP traffic through an interface to a far interface.

“For security purposes the security appliance does  not support far-end interface ping, that is pinging the IP address of  the outside interface from the inside network.”



Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: