<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX unable to ping outside from inside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761330#M534071</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The configuration was correct. host1 can ping host2.&lt;/P&gt;&lt;P&gt;I was only wrongly testing cause i was referencing outside interface, that , as you said never answers to ping.&lt;/P&gt;&lt;P&gt; Thanks for the support!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mauro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Aug 2011 08:17:23 GMT</pubDate>
    <dc:creator>fattore73</dc:creator>
    <dc:date>2011-08-09T08:17:23Z</dc:date>
    <item>
      <title>PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761323#M534064</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;I' d like to have some support for a very-basic PIX firewall configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I 'm dealing with&amp;nbsp; PIX 515 's inside/outside/dmz zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside hosts can ping inside interface , outside hosts outside interface and so on....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; text-decoration: underline; "&gt;I cannot ping outside interface from inside hosts. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;(i.e&amp;nbsp; ping 192.168.02 from 10.10.10.100)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inside network 10.10.10.0/24&lt;/P&gt;&lt;P&gt;outside network 192.168.0.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think i properly set nat and access lists, and furthermore from icmp trace it seems that translation is perfomed, but echo -reply is missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the attached file you can find the pix configuration and test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that some PIX expert can easily find out the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the support&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mauro&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:08:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761323#M534064</guid>
      <dc:creator>fattore73</dc:creator>
      <dc:date>2019-03-11T21:08:44Z</dc:date>
    </item>
    <item>
      <title>PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761324#M534065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mauro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to design issues, you would never be able to ping a remote interface on the ASA, this is not possible, although you can ping hosts which are connected to these two interfaces, if you are facing an issue with that, do let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 07:11:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761324#M534065</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-08T07:11:58Z</dc:date>
    </item>
    <item>
      <title>PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761325#M534066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Varun, thanks for the reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I'm not dealing with ASA , but with a Pix515 : i tested that outside interface replies to ping ( from outside hosts) and I've&amp;nbsp; read in a Pix firewall book that it would be possible to test connectivity from inside to outside by means of "ping"&lt;/P&gt;&lt;P&gt;That's happen if operator enable icmp any any outside and&amp;nbsp; define an access-lis in this way:&lt;/P&gt;&lt;P&gt;"access-list acl_out permit icmp&amp;nbsp; any any"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and apply to outside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"access-group acl_out in interface outside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I executed the last 2 tasks but ping from inside host (10.10.10.100) to outside interface (192.168.0.2) sistematically fails.&lt;/P&gt;&lt;P&gt; I cannot even ping from inside host ( 10.10.10.100) to an outside host ( 192.168.0.x)&lt;/P&gt;&lt;P&gt;PiX firewall send the echo-request to outside I guess ( because NAT translations occurs) but no echo-reply ever happens.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 08:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761325#M534066</guid>
      <dc:creator>fattore73</dc:creator>
      <dc:date>2011-08-08T08:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761326#M534067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mauro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M sorry, i meant PIX, but it is true for pix as well, you would not be able to ping remote interafce on the firewall. &lt;/P&gt;&lt;P&gt;"I've&amp;nbsp; read in a Pix firewall book that it would be possible to test connectivity from inside to outside by means of "ping" "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What this means is if you have two hosts connected to the inside and outside, then it would ping, like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host1 ----------------------------outside(&lt;STRONG&gt;PIX&lt;/STRONG&gt;)inside----------------------------------host2&lt;/P&gt;&lt;P&gt;10.1.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20.1.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you would be able to ping from host2 to host1 but not host2 to outside interface, that is not possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For pinging from host2 to host1, you would need the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out_in permit icmp any any&lt;/P&gt;&lt;P&gt;access-group out_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 20.1.1.1 255.255.255.255&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this should work for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 08:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761326#M534067</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-08T08:45:58Z</dc:date>
    </item>
    <item>
      <title>PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761327#M534068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Your drawing is a good idea and useful to undestand the matter. I try to track again your approach :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; in my case host2 (20.1.1.1) can ping inside( 20.1.1.2) ........ ok!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host1(10.1.1.1) can ping outside(10.1.1.2)&amp;nbsp; ........ok!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I can take for grant that host2 cannot ping outside interface ( from you statement). ...........ok!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; You finally state that host2 can ping host 1 with the following additional commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; a)access-list out_in permit icmp any any ---&amp;gt; got it ( access-list acl_out permit icmp any any)...ok!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; b)access-group out_in in interface outside----&amp;gt; got it ( access-group acl_out in interface outside)....ok!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; c) " nat (inside) 1 20.1.1.1 255.255.255.255"&amp;nbsp;&amp;nbsp;&amp;nbsp; ------&amp;gt; should not be act as my command "nat(inside) 1 0 0 "??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; d) global (outside) 1 interface -----&amp;gt; what does it excutes? natting with&amp;nbsp; only-outside interface ip address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; should not be similar to&amp;nbsp; my command "global (outside) 1 192.168.0.10-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A&gt;&lt;/A&gt;192.168.0.62"&amp;nbsp; &lt;A&gt;&lt;/A&gt;&lt;A&gt;&lt;/A&gt;which instead define a pool of outside addresses for natting?&lt;A&gt;&lt;/A&gt;&lt;A&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; If these assumptions are true, I would already have nat and global command in my configuration properly set , but I tested that host2 cannot ping host1 up to now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 09:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761327#M534068</guid>
      <dc:creator>fattore73</dc:creator>
      <dc:date>2011-08-08T09:44:49Z</dc:date>
    </item>
    <item>
      <title>PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761328#M534069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mauro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The nat statements that i gave you were only for reference, you can use any value that you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can either use:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 20.1.1.1 255.255.255.255&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat(inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (outside) 1 192.168.0.10-192.168.0.62&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;both are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you said that you are not able to ping host2 from host1????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to troubleshoot it, plz take logs and debugs and check where the traffic dropping.&lt;/P&gt;&lt;P&gt;Take captures as well. As per the configuration it should work.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1222"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 09:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761328#M534069</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-08T09:59:08Z</dc:date>
    </item>
    <item>
      <title>PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761329#M534070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for the hint!&lt;/P&gt;&lt;P&gt;&amp;nbsp; I'll test again with capture switch on . Hope this help to collect more info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&amp;nbsp; Mauro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 11:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761329#M534070</guid>
      <dc:creator>fattore73</dc:creator>
      <dc:date>2011-08-08T11:14:59Z</dc:date>
    </item>
    <item>
      <title>PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761330#M534071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The configuration was correct. host1 can ping host2.&lt;/P&gt;&lt;P&gt;I was only wrongly testing cause i was referencing outside interface, that , as you said never answers to ping.&lt;/P&gt;&lt;P&gt; Thanks for the support!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mauro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2011 08:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761330#M534071</guid>
      <dc:creator>fattore73</dc:creator>
      <dc:date>2011-08-09T08:17:23Z</dc:date>
    </item>
    <item>
      <title>PIX unable to ping outside from inside</title>
      <link>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761331#M534072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mauro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats good, I am glad I was able to clear your doubts &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take care&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2011 08:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-unable-to-ping-outside-from-inside/m-p/1761331#M534072</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-09T08:20:29Z</dc:date>
    </item>
  </channel>
</rss>

