<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot ping interfaces on PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670345#M496951</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I already have everything it shows...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz1_in permit ip host helix-local any &lt;/P&gt;&lt;P&gt;access-list dmz1_in permit ip 192.168.140.0 255.255.255.0 host helix-local &lt;/P&gt;&lt;P&gt;access-list dmz1_in permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_in permit icmp any any &lt;/P&gt;&lt;P&gt;icmp permit any outside &lt;/P&gt;&lt;P&gt;icmp permit any inside &lt;/P&gt;&lt;P&gt;icmp permit any dmz1 &lt;/P&gt;&lt;P&gt;ip address outside 1.1.1.2 255.255.255.224 &lt;/P&gt;&lt;P&gt;ip address inside 192.168.140.3 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip address dmz1 10.10.240.2 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 1.1.1.10-1.1.1.20 netmask 255.255.255.224 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;static (dmz1,outside) helix-internet helix-local netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (dmz1,inside) 10.10.240.0 10.10.240.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 192.168.140.0 192.168.140.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;access-group dmz1_in in interface dmz1 &lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.1.1.1 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Oct 2006 12:26:59 GMT</pubDate>
    <dc:creator>cybrsage</dc:creator>
    <dc:date>2006-10-27T12:26:59Z</dc:date>
    <item>
      <title>Cannot ping interfaces on PIX</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670343#M496949</link>
      <description>&lt;P&gt;I can ping the local interface, but not the other two interfaces (Inside cannot ping DMZ, etc).  Machines in each respective area cannot ping machines in any other area either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config, any help would be appreciated (config has non-relevant items removes):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 dmz1 security10&lt;/P&gt;&lt;P&gt;(standard fixup lines)&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.10.240.10 helix-local&lt;/P&gt;&lt;P&gt;name 1.1.1.5 helix-internet&lt;/P&gt;&lt;P&gt;access-list dmz1_in permit ip host helix-local any &lt;/P&gt;&lt;P&gt;access-list dmz1_in permit ip 192.168.140.0 255.255.255.0 host helix-local &lt;/P&gt;&lt;P&gt;access-list dmz1_in permit icmp any any&lt;/P&gt;&lt;P&gt;access-list outside_in permit icmp any any &lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any dmz1&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu dmz1 1500&lt;/P&gt;&lt;P&gt;ip address outside 1.1.1.2 255.255.255.224&lt;/P&gt;&lt;P&gt;ip address inside 192.168.140.3 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz1 10.10.240.2 255.255.255.0&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;failover poll 7&lt;/P&gt;&lt;P&gt;failover ip address outside 1.1.41.3&lt;/P&gt;&lt;P&gt;failover ip address inside 192.168.140.4&lt;/P&gt;&lt;P&gt;failover ip address dmz1 10.10.240.3&lt;/P&gt;&lt;P&gt;failover link inside&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 1.1.1.10-1.1.1.20 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (dmz1,outside) helix-internet helix-local netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (dmz1,inside) 10.10.240.0 10.10.240.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 192.168.140.0 192.168.140.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;access-group dmz1_in in interface dmz1&lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.1.1.1 1&lt;/P&gt;&lt;P&gt;(timeouts, etc)&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet 192.168.140.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet 192.168.140.0 255.255.255.0 dmz1&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Points are always given to those who help  &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670343#M496949</guid>
      <dc:creator>cybrsage</dc:creator>
      <dc:date>2020-02-21T09:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping interfaces on PIX</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670344#M496950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/31.html" target="_blank"&gt;http://www.cisco.com/warp/public/110/31.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2006 11:38:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670344#M496950</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2006-10-27T11:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping interfaces on PIX</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670345#M496951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I already have everything it shows...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz1_in permit ip host helix-local any &lt;/P&gt;&lt;P&gt;access-list dmz1_in permit ip 192.168.140.0 255.255.255.0 host helix-local &lt;/P&gt;&lt;P&gt;access-list dmz1_in permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_in permit icmp any any &lt;/P&gt;&lt;P&gt;icmp permit any outside &lt;/P&gt;&lt;P&gt;icmp permit any inside &lt;/P&gt;&lt;P&gt;icmp permit any dmz1 &lt;/P&gt;&lt;P&gt;ip address outside 1.1.1.2 255.255.255.224 &lt;/P&gt;&lt;P&gt;ip address inside 192.168.140.3 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip address dmz1 10.10.240.2 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 1.1.1.10-1.1.1.20 netmask 255.255.255.224 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;static (dmz1,outside) helix-internet helix-local netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (dmz1,inside) 10.10.240.0 10.10.240.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 192.168.140.0 192.168.140.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;access-group dmz1_in in interface dmz1 &lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.1.1.1 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2006 12:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670345#M496951</guid>
      <dc:creator>cybrsage</dc:creator>
      <dc:date>2006-10-27T12:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping interfaces on PIX</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670346#M496952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to this config you should be able to ping hosts on the DMZ and the internet from the inside. But for some reason, you will never be able be able the DMZ or outside interface of pix from the inside. or the other way round.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2006 13:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670346#M496952</guid>
      <dc:creator>rkazmierczak</dc:creator>
      <dc:date>2006-10-27T13:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping interfaces on PIX</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670347#M496953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot ping from the inside the PIX interface on the DMZ, the PIX does not allow that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) You can ping, if you have configured the ICMP command, from the inside host the inside interface. Or from the DMZ the dmz interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) If you have configured the access-list correctly then you can ping a host on the DMZ from the inside host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) You should be able to ping everything from the PIX itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2006 14:05:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670347#M496953</guid>
      <dc:creator>Patrick Iseli</dc:creator>
      <dc:date>2006-10-27T14:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping interfaces on PIX</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670348#M496954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yet it does not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I ping from the Inside to the DMZ, the ping trace shows the requests and translation happening but does not show any replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I ping from the DMZ to the Inside, the ping trace shows requests, translations, and replies, but the PC shows no reply (100% failure).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2006 14:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670348#M496954</guid>
      <dc:creator>cybrsage</dc:creator>
      <dc:date>2006-10-27T14:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot ping interfaces on PIX</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670349#M496955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First make sure that the hosts definately respond to pings (ping them from the local lan).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they do, there is only one explanation: a slight pix mulfunction, so to say. I had a simmilar problem once. I configured everything correctly but still it didn't work. After a reboot it worked fine. but it did start to work. From what you are saying it doesn't work for a longer time and that is strange &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to remove and reapply the ACL, reboot etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In software 7.0 and higher you can enable icmp inspection which would allow to pings to come back event without the access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rafal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Oct 2006 07:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-interfaces-on-pix/m-p/670349#M496955</guid>
      <dc:creator>rkazmierczak</dc:creator>
      <dc:date>2006-10-28T07:41:25Z</dc:date>
    </item>
  </channel>
</rss>

