<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Outside Interface Ping Reply? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679627#M1022943</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to block icmp to your outside pix interface from config mode on the pix &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"no icmp permit any outside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can be more granular than this and allow certain addresses to ping your outside interface rather than deny all addresses as the above command does. I don't know whether you need this or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 18 Mar 2007 15:33:22 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-03-18T15:33:22Z</dc:date>
    <item>
      <title>PIX Outside Interface Ping Reply?</title>
      <link>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679626#M1022939</link>
      <description>&lt;P&gt;I'm fairly new to PIX and recently configured a new 506e running 6.3(5). Something I noticed straight after bringing the outside interface up was that I could ping the outside IP address from the internet (from different ISP). Is it suppose to be this way? I thought a PIX would block this by default? If this is correct, how do I block replies from this interface?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679626#M1022939</guid>
      <dc:creator>jrossouw</dc:creator>
      <dc:date>2019-03-11T09:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Outside Interface Ping Reply?</title>
      <link>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679627#M1022943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to block icmp to your outside pix interface from config mode on the pix &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"no icmp permit any outside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can be more granular than this and allow certain addresses to ping your outside interface rather than deny all addresses as the above command does. I don't know whether you need this or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Mar 2007 15:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679627#M1022943</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-18T15:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Outside Interface Ping Reply?</title>
      <link>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679628#M1022945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon. Thanks! That certainly helped. The answer is slightly different though. It should be "icmp deny any outside". That's all I needed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Mar 2007 15:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679628#M1022945</guid>
      <dc:creator>jrossouw</dc:creator>
      <dc:date>2007-03-18T15:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Outside Interface Ping Reply?</title>
      <link>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679629#M1022947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Johan &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry about that, i slipped into IOS mode there &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for the rating &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Mar 2007 17:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-outside-interface-ping-reply/m-p/679629#M1022947</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-18T17:09:13Z</dc:date>
    </item>
  </channel>
</rss>

