[c-nsp] traceroute from ASA with source IP from inside interface

Nick Hilliard nick at foobar.org
Wed Mar 16 08:42:15 EDT 2016

George Giannousopoulos wrote:
> It's been a while since I tried that, but I think you are not allowed by
> default to ping an outside host using an inside interface as the source.
> Each interface can successfully ping only on it's egress direction unless
> you change the rules.

last time I checked, this was a hard limitation on ASA which couldn't be
worked around by changing the FW rulesets.


