<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VERY basic pix 515 question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618149#M1023803</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well... it looks like the fun is over... pix wont boot any longer after the re-flash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checksum verification on compression loader failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it just reboots over and over..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;during the tftp flash it got a lot of timeouts before it started sending the image then it complete and got that error listed above ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bad flash ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Mar 2007 02:56:29 GMT</pubDate>
    <dc:creator>garcia.mike1</dc:creator>
    <dc:date>2007-03-13T02:56:29Z</dc:date>
    <item>
      <title>VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618139#M1023786</link>
      <description>&lt;P&gt;I am new to the whole security world... ie. configuring pixes... I have a question, I was given (free) pix 515 with the two interfaces... I did a wr erase on it to start fresh, but wanted to test the ports for connectivity...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured my outside interface with 10.1.1.1/24 and a host 10.1.1.2/24 did a ping and got a reply... good&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;next i erased that config and did inside the same way, but when my host pings i get no reply and when the pix pings the host it gets no replay... got a up/up on the interface did a permit icmp any any and permit ip any any and noting... is the pix broken ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what can i do to test...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;non production environment BTW &lt;/P&gt;&lt;P&gt;also the host is connected DIRECTLY to eth0 and eth1 &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618139#M1023786</guid>
      <dc:creator>garcia.mike1</dc:creator>
      <dc:date>2019-03-11T09:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618140#M1023787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you clear the ARP cache on the host when connecting to the inside interface of PIX? When trying to ping the inside interface of PIX, please enable debugs on PIX and logging also to see if ICMP packets are reaching the inside interface-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug icmp trace&lt;/P&gt;&lt;P&gt;logg con 7&lt;/P&gt;&lt;P&gt;logg on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now try pinging again and let me know what you see on the console connection of PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 16:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618140#M1023787</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-08T16:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618141#M1023788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firstly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the firewall (from config mode) can you ping the inside Interface ? If no then certainly you have a bad firewall that you are playing with &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here I assume that you have assigned the ip address to inside, security level,int status up/up, and other basic commands needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly make sure you dont have an icmp deny for inside, which ideally should not be if you have erased the config and starting from scratch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in any case to verify this use the command "sh  icmp"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please use the following command on firewall to make sure if the arp entries are building up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh arp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also verify this on windows machine if it is populating Pix Inside Mac address using the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;arp -a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lastly yes...make sure the packet is at least reaching the firewall using the command debug icmp trace...if none of the icmp request is hitting the firewall...then you have to bang your pc...and chop  the cable that you are  using...:-)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 04:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618141#M1023788</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-09T04:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618142#M1023789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;k.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping from pix to inside got a reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# ping 192.168.1.2&lt;/P&gt;&lt;P&gt;13: ICMP echo request (len 32 id 9233 seq 0) 192.168.1.1 &amp;gt; 192.168.1.2&lt;/P&gt;&lt;P&gt;        192.168.1.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;14: ICMP echo request (len 32 id 9233 seq 1) 192.168.1.1 &amp;gt; 192.168.1.2&lt;/P&gt;&lt;P&gt;        192.168.1.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;15: ICMP echo request (len 32 id 9233 seq 2) 192.168.1.1 &amp;gt; 192.168.1.2&lt;/P&gt;&lt;P&gt;        192.168.1.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;pix# 111008: User 'enable_15' executed the 'ping 192.168.1.2' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# ping 192.168.1.1&lt;/P&gt;&lt;P&gt;        192.168.1.1 response received -- 0ms&lt;/P&gt;&lt;P&gt;        192.168.1.1 response received -- 0ms&lt;/P&gt;&lt;P&gt;        192.168.1.1 response received -- 0ms&lt;/P&gt;&lt;P&gt;pix# 111008: User 'enable_15' executed the 'ping 192.168.1.1' command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;workstation is using 192.168.1.2&lt;/P&gt;&lt;P&gt;Pix is using 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config&lt;/P&gt;&lt;P&gt;pix# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;hostname pix&lt;/P&gt;&lt;P&gt;domain-name home&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names         &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging console debugging&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;no ip address outside&lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;conduit permit icmp any any &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3 &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10 &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3 &lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10 &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:e1f71a437b169145a15aa8ed4e87d318&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;pix# 111009: User 'enable_15' executed cmd: show running-config&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 17:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618142#M1023789</guid>
      <dc:creator>garcia.mike1</dc:creator>
      <dc:date>2007-03-09T17:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618143#M1023791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;interface ethernet1 "inside" is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82559 ethernet, address is 0050.54ff.6389&lt;/P&gt;&lt;P&gt;  IP address 192.168.1.1, subnet mask 255.255.255.0&lt;/P&gt;&lt;P&gt;  MTU 1500 bytes, BW 100000 Kbit full duplex&lt;/P&gt;&lt;P&gt;        103 packets input, 15307 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;        Received 103 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        64 packets output, 3840 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;        0 babbles, 0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        0 lost carrier, 0 no carrier&lt;/P&gt;&lt;P&gt;        input queue (curr/max blocks): hardware (128/128) software (0/1)&lt;/P&gt;&lt;P&gt;        output queue (curr/max blocks): hardware (0/1) software (0/1)&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;111009: User 'enable_15' executed cmd: show interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 17:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618143#M1023791</guid>
      <dc:creator>garcia.mike1</dc:creator>
      <dc:date>2007-03-09T17:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618144#M1023793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;awrite..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping from a machine 192.168.1.2 to the firewall 192.168.1.1 and send me the debug icmp trace...do you see anything from your pc hitting the firewall back ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what about arp -a on machine..? do you see this address  0050.54ff.6389 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 18:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618144#M1023793</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-09T18:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618145#M1023795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got this error when booting UP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;32MB RAM&lt;/P&gt;&lt;P&gt;imgsum_config: sumval(0x5d38) md5(0x525ac23a 0x029b65fa 0x9b9c1ed3 0x6f7c4cad)&lt;/P&gt;&lt;P&gt;imgsum_verify: chksum(0x   0) md5(0x2d8372df 0xdca29c51 0x439e5ea1 0xd4f02de3)&lt;/P&gt;&lt;P&gt;Panic: kernel - The checksum verification for this image failed.&lt;/P&gt;&lt;P&gt;=========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Secure PIX Firewall BIOS (4.0) #0: Thu Mar  2 22:59:20 PST 2000&lt;/P&gt;&lt;P&gt;Platform PIX-515&lt;/P&gt;&lt;P&gt;Flash=i28F640J5 @ 0x300&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use BREAK or ESC to interrupt flash boot.&lt;/P&gt;&lt;P&gt;Use SPACE to begin flash boot immediately.&lt;/P&gt;&lt;P&gt;Reading 1974784 bytes of image from flash.      &lt;/P&gt;&lt;P&gt;#################################################################################################################&lt;/P&gt;&lt;P&gt;32MB RAM&lt;/P&gt;&lt;P&gt;imgsum_config: sumval(0x5d38) md5(0x525ac23a 0x029b65fa 0x9b9c1ed3 0x6f7c4cad)&lt;/P&gt;&lt;P&gt;imgsum_verify: chksum(0x   0) md5(0xab907943 0x9824133c 0x5433a1b9 0xbc6c7c6a)&lt;/P&gt;&lt;P&gt;Panic: kernel - The checksum verification for this image failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;about 3 times then booted normally&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# debug icmp trace &lt;/P&gt;&lt;P&gt;ICMP trace on&lt;/P&gt;&lt;P&gt;Warning: this may cause problems on busy networks&lt;/P&gt;&lt;P&gt;pix# ping 192.168.1.2&lt;/P&gt;&lt;P&gt;1: ICMP echo request (len 32 id 9233 seq 0) 192.168.1.1 &amp;gt; 192.168.1.2&lt;/P&gt;&lt;P&gt;        192.168.1.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;2: ICMP echo request (len 32 id 9233 seq 1) 192.168.1.1 &amp;gt; 192.168.1.2&lt;/P&gt;&lt;P&gt;        192.168.1.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;3: ICMP echo request (len 32 id 9233 seq 2) 192.168.1.1 &amp;gt; 192.168.1.2&lt;/P&gt;&lt;P&gt;        192.168.1.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;pix# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;machine 2 pix&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ethernet adapter Local Area Connection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        Connection-specific DNS Suffix  . :&lt;/P&gt;&lt;P&gt;        IP Address. . . . . . . . . . . . : 192.168.1.2&lt;/P&gt;&lt;P&gt;        Subnet Mask . . . . . . . . . . . : 255.255.255.0&lt;/P&gt;&lt;P&gt;        Default Gateway . . . . . . . . . :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\mgarcia&amp;gt;ping 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pinging 192.168.1.1 with 32 bytes of data:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Request timed out.&lt;/P&gt;&lt;P&gt;Request timed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;arp -a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\mgarcia&amp;gt;arp -a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface: 172.16.1.17 --- 0x2&lt;/P&gt;&lt;P&gt;  Internet Address      Physical Address      Type&lt;/P&gt;&lt;P&gt;  172.16.1.1            00-0f-66-9d-0f-91     dynamic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;above was wireless card not the card connected to pix.. ??? IS the OS screwed up on this thing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and one more time the counters for this alleged bad interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet1 "inside" is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82559 ethernet, address is 0050.54ff.6389&lt;/P&gt;&lt;P&gt;  IP address 192.168.1.1, subnet mask 255.255.255.0&lt;/P&gt;&lt;P&gt;  MTU 1500 bytes, BW 100000 Kbit full duplex&lt;/P&gt;&lt;P&gt;        5 packets input, 682 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;        Received 5 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        20 packets output, 1200 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;        0 babbles, 0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        0 lost carrier, 0 no carrier&lt;/P&gt;&lt;P&gt;        input queue (curr/max blocks): hardware (128/128) software (0/1)&lt;/P&gt;&lt;P&gt;        output queue (curr/max blocks): hardware (0/1) software (0/1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Mar 2007 00:06:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618145#M1023795</guid>
      <dc:creator>garcia.mike1</dc:creator>
      <dc:date>2007-03-11T00:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618146#M1023796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well few  more things that we can try :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Can you ping the local machine (192.168.1.2) from any other m achine ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)Can you please set the default  gateway on  this machine as 192.168.1.1 and then ping the firewall, though you dont need a default gateway if the detination ip is in the same subnet,but lets set the DG and then try pinging the inside interface of the FW&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)the firewall should not give those checksum verification failed messages.....can you reinstall a new image and then try... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2007 17:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618146#M1023796</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-12T17:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618147#M1023799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may be getting a reply, but maybe you don't see it.  You should add the ACL to allow Echo Replys, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;samle lines:&lt;/P&gt;&lt;P&gt;access-list outside_int_name permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list outside_int_name permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;access-list outside_int_name permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;outside_int_name = the name of your outside Interface name.  Whatever you called it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2007 23:17:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618147#M1023799</guid>
      <dc:creator>flopez</dc:creator>
      <dc:date>2007-03-12T23:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618148#M1023801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem isnt the outside interface... its the inside that is the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2007 02:10:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618148#M1023801</guid>
      <dc:creator>garcia.mike1</dc:creator>
      <dc:date>2007-03-13T02:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618149#M1023803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well... it looks like the fun is over... pix wont boot any longer after the re-flash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checksum verification on compression loader failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it just reboots over and over..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;during the tftp flash it got a lot of timeouts before it started sending the image then it complete and got that error listed above ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bad flash ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2007 02:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618149#M1023803</guid>
      <dc:creator>garcia.mike1</dc:creator>
      <dc:date>2007-03-13T02:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618150#M1023805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basicly if you want to ping from the inside network to the inside interface of the PIX then you need to allow this by the &amp;lt; icmp &amp;gt; command !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit|deny [host] src_addr [src_mask] [type] int_name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to allow pings through multiple interfaces you need to configure an access-list.&lt;/P&gt;&lt;P&gt;example you want to ping from an inside host to and internet IP (www.yahoo.com).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any host 200.1.1.5 echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any host 200.1.1.5 source-quench&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any host 200.1.1.5 unreachable&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any host 200.1.1.5 time-exceeded&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference:&lt;/P&gt;&lt;P&gt;Handling ICMP Pings with the PIX Firewall: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800e9312.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800e9312.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2007 03:10:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618150#M1023805</guid>
      <dc:creator>Patrick Iseli</dc:creator>
      <dc:date>2007-03-13T03:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: VERY basic pix 515 question</title>
      <link>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618151#M1023806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes its bad flash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have two options :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)Contact Cisco-TAC and if you have relevant contract ask them to RMA the device &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)Try uploading a new image from the monitor mode (during boot process hit the escape key and it will take you to monitor mode)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2007 16:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/very-basic-pix-515-question/m-p/618151#M1023806</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-13T16:47:50Z</dc:date>
    </item>
  </channel>
</rss>

