<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nested Firewalls in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915152#M456955</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have the PIX501 on the LAN and not directly facing the Internet can you try adding the command and try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;icmp permit any outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to be more specific the command format is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;icmp permit &lt;NETWORK&gt; &lt;NETWORK mask=""&gt; &lt;INTERFACE name=""&gt;&lt;/INTERFACE&gt;&lt;/NETWORK&gt;&lt;/NETWORK&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Apr 2012 16:43:35 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-04-17T16:43:35Z</dc:date>
    <item>
      <title>Nested Firewalls</title>
      <link>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915151#M456954</link>
      <description>&lt;P&gt;I am not able to ping a public IP address of 4.2.2.2 from a device on my network.&amp;nbsp; Does anyone have Ideas what could be preventing this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A little about my network:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP &amp;gt; Pix 515 &amp;gt; Switch &amp;gt; Pix 501 &amp;gt; Device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix 515 &lt;/P&gt;&lt;P&gt;outside dhcp setroute&lt;/P&gt;&lt;P&gt;inside(10.100.60.1/16)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch&lt;/P&gt;&lt;P&gt;--All Users except pix 501 are connected to it recieve an IP address and are able to ping 4.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix 501&lt;/P&gt;&lt;P&gt;outside dhcp setroute&lt;/P&gt;&lt;P&gt;inside (172.16.0.1/24)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix recieved a 10.100.60.0 /16 address.&lt;/P&gt;&lt;P&gt;Pix is able to ping 10.100.60.1&lt;/P&gt;&lt;P&gt;Pix is NOT ABLE to ping 4.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===PING TEST===&lt;/P&gt;&lt;P&gt;DansFW(config)# ping 10.100.60.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.100.60.1 response received -- 0ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.100.60.1 response received -- 0ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.100.60.1 response received -- 0ms&lt;/P&gt;&lt;P&gt;DansFW(config)# ping 4.2.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.2.2.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.2.2.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.2.2.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===ROUTING INFO===&lt;/P&gt;&lt;P&gt;DansFW(config)# show route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside 0.0.0.0 0.0.0.0 10.100.60.1 1 DHCP static&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside 10.100.0.0 255.255.0.0 10.100.60.23 1 CONNECT static&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.16.0.0 255.255.255.0 172.16.0.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=====CONFIG ===&lt;/P&gt;&lt;P&gt;&lt;A href="https://gist.github.com/2406839" target="_blank"&gt;https://gist.github.com/2406839&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915151#M456954</guid>
      <dc:creator>danbryan80</dc:creator>
      <dc:date>2019-03-11T22:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Nested Firewalls</title>
      <link>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915152#M456955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have the PIX501 on the LAN and not directly facing the Internet can you try adding the command and try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;icmp permit any outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to be more specific the command format is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;icmp permit &lt;NETWORK&gt; &lt;NETWORK mask=""&gt; &lt;INTERFACE name=""&gt;&lt;/INTERFACE&gt;&lt;/NETWORK&gt;&lt;/NETWORK&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 16:43:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915152#M456955</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-04-17T16:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: Nested Firewalls</title>
      <link>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915153#M456956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the suggestion, but it appears to be the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DansFW(config)# icmp permit any outside&lt;/P&gt;&lt;P&gt;DansFW(config)# ping 4.2.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.2.2.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.2.2.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.2.2.2 NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;DansFW(config)# ping 10.100.60.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.100.60.1 response received -- 0ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.100.60.1 response received -- 0ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.100.60.1 response received -- 0ms&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 20:52:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915153#M456956</guid>
      <dc:creator>danbryan80</dc:creator>
      <dc:date>2012-04-17T20:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Nested Firewalls</title>
      <link>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915154#M456957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you enabled "inspect icmp" in the PIX515?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And have you also allowed ICMPs in the PIX515 access-list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 23:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915154#M456957</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-04-17T23:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Nested Firewalls</title>
      <link>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915155#M456958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its a Pix 501, and it doesnt seem to support the command inspect.&amp;nbsp; It is however passing data.&amp;nbsp; I hooked a client up to it and the client is able to browse. Just ping seems to fail.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2012 14:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915155#M456958</guid>
      <dc:creator>danbryan80</dc:creator>
      <dc:date>2012-04-18T14:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Nested Firewalls</title>
      <link>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915156#M456959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I meant the PIX515 at the edge of the network. Aint the PIX501 behind it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though now that I think of it I guess you already have the "inspect icmp" rule enabled on the PIX515 if the hosts on its inside can ping the address you mentioned? Aint the users in the same network as PIX501 outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you been checking the logs on the PIX515 to see if theres any echo replies coming from the target IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not totally sure if an old PIX501 has any addiotional configurations needed to allow ICMP when your using its interface to ping something instead of a host behind it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think though that theres guides on how to configure the PIX to handle ICMP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to attach an access-list on the outside interface of the PIX501 in the direction "in" and allowing ICMP to the outside interface? Or if you have an access-list already configured, add a permit line to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2012 15:43:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nested-firewalls/m-p/1915156#M456959</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-04-18T15:43:32Z</dc:date>
    </item>
  </channel>
</rss>

