![Cisco ASA 5512-X Скачать руководство пользователя страница 295](http://html.mh-extra.com/html/cisco/asa-5512-x/asa-5512-x_configuration-manual_63717295.webp)
13-7
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 13 Troubleshooting Connections and Resources
Testing Your Configuration
Figure 13-3
Ping Failure Because of IP Addressing Problems
Step 3
Ping each ASA interface from a remote host. For transparent mode, ping the management IP address.
This test checks whether the directly connected router can route the packet between the host and the
ASA, and whether the ASA can correctly route the packet back to the host.
A ping might fail if the ASA does not have a return route to the host through the intermediate router (see
the following figure). In this case, the debugging messages show that the ping was successful, but syslog
message 110001 appears, indicating a routing failure has occurred.
Figure 13-4
Ping Failure Because the ASA Has No Return Route
Step 4
Ping from an ASA interface to a network device that you know is functioning correctly.
•
If the ping is not received, a problem with the transmitting hardware or interface configuration may
exist.
•
If the ASA interface is configured correctly and it does not receive an echo reply from the “known
good” device, problems with the interface hardware receiving function may exist. If a different
interface with “known good” receiving capability can receive an echo after pinging the same “known
good” device, the hardware receiving problem of the first interface is confirmed.
Step 5
Ping from the host or router through the source interface to another host or router on another interface.
Repeat this step for as many interface pairs as you want to check. If you use NAT, this test shows that
NAT is operating correctly.
If the ping succeeds, a syslog message appears to confirm the address translation for routed mode
(305009 or 305011) and that an ICMP connection was established (302020). You can also enter either
the
show xlate
or
show conns
command to view this information.
The ping might fail because NAT is not configured correctly. In this case, a syslog message appears,
showing that the NAT failed (305005 or 305006). If the ping is from an outside host to an inside host,
and you do not have a static translation, you get message 106010.
Figure 13-5
Ping Failure Because the ASA is Not Translating Addresses
192.16
8
.1.1
192.16
8
.1.2
192.16
8
.1.2
Ping
Ro
u
ter
S
ec
u
rity
Appli
a
nce
Ho
s
t
126696
Ping
A
S
A
Ro
u
ter
33
0
8
60
Ping
Ro
u
ter
Ro
u
ter
Ho
s
t
Ho
s
t
S
ec
u
rity
Appli
a
nce
126694
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...