<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ping PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ping-pix/m-p/521576#M526394</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should get you started:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R4:&lt;/P&gt;&lt;P&gt;no ip route 10.1.1.1 255.255.255.0 20.1.24.254 &lt;/P&gt;&lt;P&gt;ip route 10.1.1.0 255.255.255.0 20.1.24.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX:&lt;/P&gt;&lt;P&gt;ip address outside 20.1.24.254 255.255.255.0&lt;/P&gt;&lt;P&gt;no static (inside,outside) 20.x.x.x.x.1.1 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) 10.1.1.0 10.1.1.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;access-list MYACLOUT permit icmp any any&lt;/P&gt;&lt;P&gt;no access-list MYACLOUT permit ip host 20.1.24.4 host 10.1.1.1&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 &lt;GATEWAY ip=""&gt; &lt;/GATEWAY&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Apr 2006 14:59:36 GMT</pubDate>
    <dc:creator>laurent.geyer</dc:creator>
    <dc:date>2006-04-13T14:59:36Z</dc:date>
    <item>
      <title>Ping PIX</title>
      <link>https://community.cisco.com/t5/network-security/ping-pix/m-p/521570#M526388</link>
      <description>&lt;P&gt;[R4] --- PIX --- [R1]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to configure a static route for 10.1.1.x network on R4 and configure PIX so that R4&lt;/P&gt;&lt;P&gt;can ping 10.1.1.1 (R1). But, the configuration does not seem to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt;ip address 20.x.x.x.x.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip route 10.1.1.1 255.255.255.0 20.1.24.254&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nameif ethernet0 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet1 outside security0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip address inside 10.1.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address outside 20.x.x.x.x.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;static (inside,outside) 20.x.x.x.x.1.1 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-list MYACLOUT permit ip host 20.1.24.4 host 10.1.1.1&lt;/P&gt;&lt;P&gt;access-group MYACLOUT in interface outside&lt;/P&gt;&lt;P&gt;icmp permit host 20.1.24.4 echo outside &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;icmp deny any outside&lt;/P&gt;&lt;P&gt;icmp deny any inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt;ip address 10.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping does not work ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R4# ping 10.1.1.1&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:46:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-pix/m-p/521570#M526388</guid>
      <dc:creator>gnaveen</dc:creator>
      <dc:date>2020-02-21T08:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Ping PIX</title>
      <link>https://community.cisco.com/t5/network-security/ping-pix/m-p/521571#M526389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try the following config on the PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.1.1.1 10.1.1.1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;instead of:&lt;/P&gt;&lt;P&gt;static (inside,outside) 20.1.24.4 10.1.1.1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps - pls rate the post if it does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paresh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Mar 2006 03:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-pix/m-p/521571#M526389</guid>
      <dc:creator>pkhatri</dc:creator>
      <dc:date>2006-03-16T03:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ping PIX</title>
      <link>https://community.cisco.com/t5/network-security/ping-pix/m-p/521572#M526390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, it did not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R4#ping 20.1.24.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 20.1.24.254, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms&lt;/P&gt;&lt;P&gt;R4#ping 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;R4#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Mar 2006 14:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-pix/m-p/521572#M526390</guid>
      <dc:creator>gnaveen</dc:creator>
      <dc:date>2006-03-16T14:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Ping PIX</title>
      <link>https://community.cisco.com/t5/network-security/ping-pix/m-p/521573#M526391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, it did not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R4#ping 20.1.24.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 20.1.24.254, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms&lt;/P&gt;&lt;P&gt;R4#ping 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;R4#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Mar 2006 15:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-pix/m-p/521573#M526391</guid>
      <dc:creator>gnaveen</dc:creator>
      <dc:date>2006-03-16T15:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ping PIX</title>
      <link>https://community.cisco.com/t5/network-security/ping-pix/m-p/521574#M526392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the icmp permit host 20.1.24.4 echo outside is allowing the host 20.1.24.2 to ping the pix, not the server that you have the static for.  Add ICMP to your access-list and you should be good to go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list MYACLOUT permit icmp any host 20.1.24.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Mar 2006 16:29:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-pix/m-p/521574#M526392</guid>
      <dc:creator>bcarroll</dc:creator>
      <dc:date>2006-03-16T16:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Ping PIX</title>
      <link>https://community.cisco.com/t5/network-security/ping-pix/m-p/521575#M526393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Simple!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to have a route back, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type the following command on R1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 20.0.0.0 255.0.0.0 10.1.1.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should work after that...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the best.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Apr 2006 13:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-pix/m-p/521575#M526393</guid>
      <dc:creator>oabduo983</dc:creator>
      <dc:date>2006-04-03T13:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ping PIX</title>
      <link>https://community.cisco.com/t5/network-security/ping-pix/m-p/521576#M526394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should get you started:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R4:&lt;/P&gt;&lt;P&gt;no ip route 10.1.1.1 255.255.255.0 20.1.24.254 &lt;/P&gt;&lt;P&gt;ip route 10.1.1.0 255.255.255.0 20.1.24.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX:&lt;/P&gt;&lt;P&gt;ip address outside 20.1.24.254 255.255.255.0&lt;/P&gt;&lt;P&gt;no static (inside,outside) 20.x.x.x.x.1.1 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) 10.1.1.0 10.1.1.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;access-list MYACLOUT permit icmp any any&lt;/P&gt;&lt;P&gt;no access-list MYACLOUT permit ip host 20.1.24.4 host 10.1.1.1&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 &lt;GATEWAY ip=""&gt; &lt;/GATEWAY&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Apr 2006 14:59:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-pix/m-p/521576#M526394</guid>
      <dc:creator>laurent.geyer</dc:creator>
      <dc:date>2006-04-13T14:59:36Z</dc:date>
    </item>
  </channel>
</rss>

