<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 525 - Can't ping inside interface from inside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635461#M1028772</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Couple of questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you get link?  (interface shows as up when you do a show int on the pix?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using a crossover cable?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you get an arp entry on the firewall for you PC (assuming the first 2 questions are yes) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you confirmed that your PC has the correct IP address and subnet mask?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this message if it helped solve some or all of your issue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jan 2007 18:04:12 GMT</pubDate>
    <dc:creator>jgervia_2</dc:creator>
    <dc:date>2007-01-16T18:04:12Z</dc:date>
    <item>
      <title>PIX 525 - Can't ping inside interface from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635460#M1028771</link>
      <description>&lt;P&gt;This is driving me nuts, bc I can't figure it out. Please Help!&lt;/P&gt;&lt;P&gt;==============================&lt;/P&gt;&lt;P&gt;I have a new PIX 525. &lt;/P&gt;&lt;P&gt;I'm trying to upgrade the IOS, and can't even ping to get to the PC/TFTP Server. &lt;/P&gt;&lt;P&gt;It's driving me nuts. &lt;/P&gt;&lt;P&gt;I can upgrade it via Monitor Mode, no problem. &lt;/P&gt;&lt;P&gt;But I'm trying to upgrade via "copy tftp flash" command, which won't work if I &lt;/P&gt;&lt;P&gt;can't even ping. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I?m not even trying to go out. Just trying to ping the inside interface from the inside. I?ve got my PC directly connected to the Inside Interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, this is a Secondary PIX, not the primary. That shouldn?t matter should it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be grateful. &lt;/P&gt;&lt;P&gt;=======================================&lt;/P&gt;&lt;P&gt;PC/TFTP Server (directly connected to PIX Inside interface)&lt;/P&gt;&lt;P&gt;10.107.16.116 255.255.255.0&lt;/P&gt;&lt;P&gt;GW 10.107.16.1&lt;/P&gt;&lt;P&gt;=======================================&lt;/P&gt;&lt;P&gt;PIX config I entered:&lt;/P&gt;&lt;P&gt;nameif e1 inside sec100&lt;/P&gt;&lt;P&gt;int e1 auto &lt;/P&gt;&lt;P&gt;ip addr inside 10.107.16.118 255.255.255.0&lt;/P&gt;&lt;P&gt;route inside 0 0 10.107.16.116&lt;/P&gt;&lt;P&gt;icmp permit 10.107.16.116 inside&lt;/P&gt;&lt;P&gt;conduit permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;PIX Config is below:&lt;/P&gt;&lt;P&gt;=======================================&lt;/P&gt;&lt;P&gt;: Written by enable_15 at 10:18:57.897 UTC Fri Jan 12 2007&lt;/P&gt;&lt;P&gt;PIX Version 6.3(1)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;interface gb-ethernet0 1000auto shutdown&lt;/P&gt;&lt;P&gt;interface gb-ethernet1 1000auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet2 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet3 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet4 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet5 auto shutdown&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif gb-ethernet0 intf2 security4&lt;/P&gt;&lt;P&gt;nameif gb-ethernet1 intf3 security6&lt;/P&gt;&lt;P&gt;nameif ethernet2 intf4 security8&lt;/P&gt;&lt;P&gt;nameif ethernet3 intf5 security10&lt;/P&gt;&lt;P&gt;nameif ethernet4 intf6 security12&lt;/P&gt;&lt;P&gt;nameif ethernet5 intf7 security14&lt;/P&gt;&lt;P&gt;enable password xxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;passwd xxxxxxxxxxxxxx  encrypted&lt;/P&gt;&lt;P&gt;hostname PIX525A&lt;/P&gt;&lt;P&gt;domain-name xxx&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol ils 389&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;icmp permit 10.107.16.116 inside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu intf2 1500&lt;/P&gt;&lt;P&gt;mtu intf3 1500&lt;/P&gt;&lt;P&gt;mtu intf4 1500&lt;/P&gt;&lt;P&gt;mtu intf5 1500&lt;/P&gt;&lt;P&gt;mtu intf6 1500&lt;/P&gt;&lt;P&gt;mtu intf7 1500&lt;/P&gt;&lt;P&gt;no ip address outside&lt;/P&gt;&lt;P&gt;ip address inside 10.107.16.118 255.255.255.0&lt;/P&gt;&lt;P&gt;no ip address intf2&lt;/P&gt;&lt;P&gt;no ip address intf3&lt;/P&gt;&lt;P&gt;no ip address intf4&lt;/P&gt;&lt;P&gt;no ip address intf5&lt;/P&gt;&lt;P&gt;no ip address intf6&lt;/P&gt;&lt;P&gt;no ip address intf7&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00 &lt;/P&gt;&lt;P&gt;failover poll 15&lt;/P&gt;&lt;P&gt;no failover ip address outside&lt;/P&gt;&lt;P&gt;no failover ip address inside&lt;/P&gt;&lt;P&gt;no failover ip address intf2&lt;/P&gt;&lt;P&gt;no failover ip address intf3&lt;/P&gt;&lt;P&gt;no failover ip address intf4&lt;/P&gt;&lt;P&gt;no failover ip address intf5&lt;/P&gt;&lt;P&gt;no failover ip address intf6&lt;/P&gt;&lt;P&gt;no failover ip address intf7&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;conduit permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community nonpublic&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;===============================&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Thanks to All in advance &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:20:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635460#M1028771</guid>
      <dc:creator>trangen</dc:creator>
      <dc:date>2019-03-11T09:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 - Can't ping inside interface from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635461#M1028772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Couple of questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you get link?  (interface shows as up when you do a show int on the pix?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using a crossover cable?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you get an arp entry on the firewall for you PC (assuming the first 2 questions are yes) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you confirmed that your PC has the correct IP address and subnet mask?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this message if it helped solve some or all of your issue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 18:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635461#M1028772</guid>
      <dc:creator>jgervia_2</dc:creator>
      <dc:date>2007-01-16T18:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 - Can't ping inside interface from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635462#M1028773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, get link light, and when I pink from PC, I can see activity light on the Inside Int.&lt;/P&gt;&lt;P&gt;No, no crossover cable, only straight through being used. &lt;/P&gt;&lt;P&gt;Yes, PC has 10.107.16.116 24 bit mask.&lt;/P&gt;&lt;P&gt;PIX, has 10.107.15.118, 24 bit mask. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, Arp entry on PIX.&lt;/P&gt;&lt;P&gt;When I enter "sh arp" nothing is replied. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 21:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635462#M1028773</guid>
      <dc:creator>trangen</dc:creator>
      <dc:date>2007-01-16T21:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 - Can't ping inside interface from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635463#M1028774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry, my bad, it did pick up the arp from the PC. &lt;/P&gt;&lt;P&gt;I had just powered it up, and the arp was empty, but then it showed up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 21:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635463#M1028774</guid>
      <dc:creator>trangen</dc:creator>
      <dc:date>2007-01-16T21:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 - Can't ping inside interface from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635464#M1028776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking at your statement above-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Yes, PC has 10.107.16.116 24 bit mask.&lt;/P&gt;&lt;P&gt;PIX, has 10.107.15.118, 24 bit mask."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PC and the PIX are on different subnets (10.107.16.0 255.255.255.0- PC, 10.107.15.0 255.255.255.0- PIX).  Are these IP Addresses/subnet masks accurate?  If not, that could be a cause of your problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2007 17:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635464#M1028776</guid>
      <dc:creator>scottic1</dc:creator>
      <dc:date>2007-01-17T17:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 525 - Can't ping inside interface from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635465#M1028779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, typo on my part, it should have said&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Yes, PC has 10.107.16.116 24 bit mask. &lt;/P&gt;&lt;P&gt;PIX, has 10.107.16.118, 24 bit mask." &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2007 21:27:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-525-can-t-ping-inside-interface-from-inside/m-p/635465#M1028779</guid>
      <dc:creator>trangen</dc:creator>
      <dc:date>2007-01-17T21:27:25Z</dc:date>
    </item>
  </channel>
</rss>

