Asa Diagnose
Ping
Icmp Ping
- ping 192.168.240.200
Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 192.168.240.200, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Tcp Ping Syn Reply
- ping tcp 192.168.240.200 53
Type escape sequence to abort. No source specified. Pinging from identity interface. Sending 5 TCP SYN requests to 192.168.240.200 port 53 from 192.168.252.185, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Tcp Ping Rst Reply
- ping tcp 192.168.240.200 25
Type escape sequence to abort. No source specified. Pinging from identity interface. Sending 5 TCP SYN requests to 192.168.240.200 port 25 from 192.168.252.185, timeout is 2 seconds: RRRRR Success rate is 0 percent (0/5
Tcp Ping with Source
!!!Wichtig - Es muss eine IP aus dem Netz aber nicht die der ASA selbst sein, weill es ansonsten ein Spoofing Deny erzeugt
- ping tcp 192.168.252.1 53 source 10.0.5.3 53
Type escape sequence to abort. Sending 5 TCP SYN requests to 192.168.252.1 port 53 from 10.0.5.3 starting port 53, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms