Internal Host Cannot Ping Virtual System
After defining a Virtual System Virtual Device on a VSX Gateway or VSX Cluster Member that implements the functionality of a Security Gateway. Acronym: VS. with an internal VLAN interface, an internal host on that VLAN cannot ping the Virtual System internal or external IP address.
Possible Causes |
How to Resolve |
A policy allowing the communication was not installed on the Virtual System. Note that after creating a Virtual System, it has a Default Policy that blocks all traffic. |
Install a policy on the Virtual System that enables the traffic. Check with the Logs & Monitor view that the Virtual System is allowing the traffic. |
There is the VLAN configuration problem on a switch, or physical cable problem. |
Check the switch configuration. Make sure that VLAN tag configured on the switch is the same as used for the Virtual System VLAN interface. Check the cables, and make sure that you have plugged the cable from the switch to the correct port on the VSX Gateway |
Incorrect routing on adjacent routers or hosts. |
Check the routing tables on intermediate routers and hosts. You can use |
Incorrect IP address or net mask defined on the Virtual System VLAN interface. |
Check the IP address and the net mask assigned to the Virtual System internal VLAN interface. |