<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP echo-request: untranslating outside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808616#M1006152</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order for you to initiate traffic from the outside, you either need a static mapping from an outside address to an inside address.  Or to exempt the traffic from translation using a "nat 0" command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Apr 2007 10:25:09 GMT</pubDate>
    <dc:creator>mark.j.hodge</dc:creator>
    <dc:date>2007-04-26T10:25:09Z</dc:date>
    <item>
      <title>ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808614#M1006148</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi please Help if you can &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to access from the outside interface using ping from a router 172.24.16.5, where there is a &lt;/P&gt;&lt;P&gt;ip route 172.24.16.8 255.255.255.255 172.24.16.7 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The device i'm trying to ping is on the inside side of the pix and has ip of 10.10.10.175 and responds to ping from the PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the router 172.24.16.5 on the outside side of the pix also reponds to pings from the pix &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enabling debug iCMP trace and pinging 172.24.16.8 from the router 172.24.16.5 i do get the following messages &lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;macaefw2# debug icmp trace &lt;/P&gt;&lt;P&gt;ICMP trace on&lt;/P&gt;&lt;P&gt;Warning: this may cause problems on busy networks&lt;/P&gt;&lt;P&gt;macaefw2# 102: ICMP echo-request from outside:172.24.16.5 to 172.24.16.8 ID=56 seq=0 length=80&lt;/P&gt;&lt;P&gt;103: ICMP echo-request: untranslating outside:172.24.16.8 to inside:10.10.10.175&lt;/P&gt;&lt;P&gt;104: ICMP echo-request from outside:172.24.16.5 to 172.24.16.8 ID=56 seq=1 length=80&lt;/P&gt;&lt;P&gt;105: ICMP echo-request: untranslating outside:172.24.16.8 to inside:10.10.10.175&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the sh log enabled i do see&lt;/P&gt;&lt;P&gt;-------------------------------- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;605005: Login permitted from 172.22.20.142/3876 to outside:172.24.16.7/ssh for user "acergy"&lt;/P&gt;&lt;P&gt;111008: User 'enable_15' executed the 'debug icmp trace' command.&lt;/P&gt;&lt;P&gt;106100: access-list acl_outside permitted icmp outside/172.24.16.5(0) -&amp;gt; inside/172.24.16.8(8) hit-cnt 1 (first hit)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also doing sh Xlate i see &lt;/P&gt;&lt;P&gt;---------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 in use, 1 most used&lt;/P&gt;&lt;P&gt;Global 172.24.16.8 Local 10.10.10.175&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The full configuration is below. Can you please tell me why ping does not work? &lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808614#M1006148</guid>
      <dc:creator>hassepedro50</dc:creator>
      <dc:date>2019-03-11T10:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808615#M1006150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;silly question: the host 10.10.10.175 has the a route back to the pix for the network 172.24.16.0/24 or default gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Emilio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 10:12:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808615#M1006150</guid>
      <dc:creator>ecouto</dc:creator>
      <dc:date>2007-04-26T10:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808616#M1006152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order for you to initiate traffic from the outside, you either need a static mapping from an outside address to an inside address.  Or to exempt the traffic from translation using a "nat 0" command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 10:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808616#M1006152</guid>
      <dc:creator>mark.j.hodge</dc:creator>
      <dc:date>2007-04-26T10:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808617#M1006154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you look the config file (Pix Problem.txt), he have an static already for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 172.24.16.8 10.10.10.175 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Emilio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 10:27:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808617#M1006154</guid>
      <dc:creator>ecouto</dc:creator>
      <dc:date>2007-04-26T10:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808618#M1006155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not silly at all. The divice is display that controls a big crane. Route probably cannot be configured on it. I'm trying a proper PC on the same network this afertnooon. Also i thing that the IP setting on the display are IP 10.10.10.175 255.255.255.0 and no default gateway &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 10:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808618#M1006155</guid>
      <dc:creator>hassepedro50</dc:creator>
      <dc:date>2007-04-26T10:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808619#M1006157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As already suggested it does look like it could be a routing issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the pix can ping the server on it's 10.10.10.175 address one thing you could do is translate the 172.24.16.5 address to the IP address of the internal interface of the pix ie &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 172.24.16.5 255.255.255.255 outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One caveat is that its clear on your full topology so this might mess other things up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 11:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808619#M1006157</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-04-26T11:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808620#M1006158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks that sort the issue. Can you please just clarify that it might not be working the other way because of the lack of defult gateway configuration on the server .175 . This is because its not a server it's a special device that controlls a huge Crane&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 12:44:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808620#M1006158</guid>
      <dc:creator>hassepedro50</dc:creator>
      <dc:date>2007-04-26T12:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808621#M1006159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes if you initiate the connection from the device it probably won't work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you could do that may work is. Instead of natting the router IP 172.24.16.5 to the inside pix interface you could NAT it to spare 10.10.10.x address. This address needs to be in the same subnet as your .175 server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So say 10.10.10.182 is spare. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 172.24.16.5 255.255.255.255 outside &lt;/P&gt;&lt;P&gt;global (inside) 1 10.10.10.182&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the address is in the same subnet as the pix internal interface then the pix should respond to the arp from your .175 server.&lt;/P&gt;&lt;P&gt;So from the .175 server you need to ping 10.10.10.182. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It might not work but it would be worth a try. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 13:01:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808621#M1006159</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-04-26T13:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808622#M1006161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amendment to previous post. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use spare IP address 10.10.10.182. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't use NAT and global statements, so remove the existing one you setup for this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (outside,inside) 10.10.10.182 172.16.24.5 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies for this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 13:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808622#M1006161</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-04-26T13:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808623#M1006162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Jon, Can you do statics like that in version 6.3(4)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Emilio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 13:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808623#M1006162</guid>
      <dc:creator>ecouto</dc:creator>
      <dc:date>2007-04-26T13:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808624#M1006164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emilio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a pix 515E running 6.3(3) and i have a lot of these type of static commands on then so i can't see why 6.3(4) wouldn't work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 13:20:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808624#M1006164</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-04-26T13:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo-request: untranslating outside</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808625#M1006166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just asking because version 6.3 and version 7 change the way of you can create statics and NATs. If you have in use must work then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Emilio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2007 13:34:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-request-untranslating-outside/m-p/808625#M1006166</guid>
      <dc:creator>ecouto</dc:creator>
      <dc:date>2007-04-26T13:34:33Z</dc:date>
    </item>
  </channel>
</rss>

