<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow ICMP with PAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961511#M440941</link>
    <description>&lt;P&gt;From what I've read, what I would like to accomplish isn't possible. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 5 static IPs. 4 for servers and 1 for the firewall. I can ping the firewall fine from the outside but can't ping the other 4 IPs. Doesn't sound like its possible to configure this since ICMP doesn't use ports and the firewall wouldn't know how to route ICMP traffic to the different IPs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone else confirm this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:18:27 GMT</pubDate>
    <dc:creator>mtehonica</dc:creator>
    <dc:date>2019-03-11T23:18:27Z</dc:date>
    <item>
      <title>Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961511#M440941</link>
      <description>&lt;P&gt;From what I've read, what I would like to accomplish isn't possible. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 5 static IPs. 4 for servers and 1 for the firewall. I can ping the firewall fine from the outside but can't ping the other 4 IPs. Doesn't sound like its possible to configure this since ICMP doesn't use ports and the firewall wouldn't know how to route ICMP traffic to the different IPs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone else confirm this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961511#M440941</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2019-03-11T23:18:27Z</dc:date>
    </item>
    <item>
      <title>Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961512#M440942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you configured the static NAT statement for the servers yet?&lt;/P&gt;&lt;P&gt;Also, have you allowed ICMP on your outside interface for those 4 static IP Addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would be able to ping once you have the above 2 configured.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 02:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961512#M440942</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-13T02:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961513#M440944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have ICMP enabled on my router public IP and can ping that fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I've configured the static NAT for my servers. For example... Public IP 96.249.40.100 (not my real ip) on port 80 maps to 192168.1.100 on port 80. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure how I'd allow ICMP through to 96.249.40.100....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 03:07:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961513#M440944</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-13T03:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961514#M440946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have access-list applied to your outside interface? You should add "permit icmp" for those addresses that you want to ping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 03:16:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961514#M440946</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-13T03:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961515#M440947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If outsidein is the access list applied on your outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outsidein extended permit icmp any (public_ip) echo-reply&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;access-list outsidein extended permit icmp any (public_ip) echo&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;access-group outsidein in interface outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note:-For version upto 8.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would be able to ping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 05:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961515#M440947</guid>
      <dc:creator>gouravbathla</dc:creator>
      <dc:date>2012-06-13T05:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961516#M440948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the following in my access list:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&amp;nbsp; access-list outside_access_in_1 remark Allow ICMP traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list outside_access_in_1 extended permit icmp any any echo-reply&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list outside_access_in_1 extended permit icmp any any unreachable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list outside_access_in_1 extended permit icmp any any time-exceeded&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that is applied to my outside interface inbound...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-group outside_access_in_1 in interface primaryisp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one of my NAT rules which...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt; object network asp-wss-3-http-vz&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (inside,primaryisp) static 96.249.40.100 service tcp www www&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to specifically allow ICMP to asp-wss-3-http-vz or to 96.249.40.100?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 12:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961516#M440948</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-13T12:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961517#M440949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ICMP type that you would need to permit is "echo" and that has not been included in the access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please add the following:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outside_access_in_1 extended permit icmp any any echo&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and you don't need to specifically allow icmp to the host/ip address.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 13:16:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961517#M440949</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-13T13:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961518#M440950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I added that but I still cannot ping anything except the IP of the actual router IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list outside_access_in_1 remark Allow ICMP traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list outside_access_in_1 extended permit icmp any any echo&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list outside_access_in_1 extended permit icmp any any echo-reply&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list outside_access_in_1 extended permit icmp any any unreachable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list outside_access_in_1 extended permit icmp any any time-exceeded&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my ASDM log when I try to ping it...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;3&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;Jun 13 2012&lt;/TD&gt;&lt;TD&gt;09:31:29&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;96.249.40.18&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;96.249.40.10&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;Deny inbound icmp src primaryisp:96.249.40.18 dst primaryisp:96.249.40.10 (type 8, code 0)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 13:32:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961518#M440950</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-13T13:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961519#M440951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is 96.249.40.10 "primaryisp" interface ip address?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 13:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961519#M440951</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-13T13:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961520#M440952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, the primaryisp interface is 96.249.40.14.&amp;nbsp; The 4 other IPs that I want to get ICMP relies from are .10 - .13.&amp;nbsp; I'm using PAT for various services (http, https, etc) on those other 4 IPs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 13:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961520#M440952</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-13T13:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961521#M440953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also need the following NAT:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service ping&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service icmp echo&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network asp-wss-3-http-vz-ping&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host &lt;REAL-IP&gt;&lt;BR /&gt;&lt;/REAL-IP&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (inside,primaryisp) static 96.249.40.10 service ping ping&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 13:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961521#M440953</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-13T13:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961522#M440954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,primaryisp) static 96.249.40.10 service ping ping&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: % Invalid input detected at '^' marker.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 14:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961522#M440954</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-13T14:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961523#M440955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bump!&amp;nbsp; Anyone suggestions on this would be appreciated!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 18:51:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961523#M440955</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-13T18:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961524#M440956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you able to staticlly nat a single IP address with all ports to a local IP address or do you only want to nat icmp?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 21:30:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961524#M440956</guid>
      <dc:creator>John Peterson</dc:creator>
      <dc:date>2012-06-13T21:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961525#M440957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already have some NAT configured but I also need to get ICMP responses on all the IPs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2012 02:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961525#M440957</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-14T02:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961526#M440958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you configure all the 5 lines advised earlier? or just 1 line?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service ping&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service icmp echo&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network asp-wss-3-http-vz-ping&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host &lt;REAL-IP&gt;&lt;BR /&gt;&lt;/REAL-IP&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (inside,primaryisp) static 96.249.40.10 service ping ping&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2012 03:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961526#M440958</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-14T03:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961527#M440959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I did all 5 lines.&amp;nbsp; When I enter "&lt;STRONG&gt;nat (inside,primaryisp) static 96.249.40.10 service &lt;TAB&gt;" I can only choose TCP or UDP.&lt;/TAB&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2012 12:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961527#M440959</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-14T12:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961528#M440960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you need to configure static PAT, or static NAT is OK?&lt;/P&gt;&lt;P&gt;From version 8.3 onwards, it seems that you won't be able to ping the static PAT IP anymore.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2012 05:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961528#M440960</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-15T05:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961529#M440961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I need to do it using PAT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2012 12:04:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961529#M440961</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-15T12:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Allow ICMP with PAT</title>
      <link>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961530#M440962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still haven't been able to figure this out. Anyone else have any ideas??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jun 2012 01:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-icmp-with-pat/m-p/1961530#M440962</guid>
      <dc:creator>mtehonica</dc:creator>
      <dc:date>2012-06-17T01:38:43Z</dc:date>
    </item>
  </channel>
</rss>

