<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem passing traffic outside the pix in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315452#M553405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eric, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a quick look at your config and one thing I noticed is that you dont't seem to have any access-group LANOut in interface inside applied, also for your reference check out the following URL on how to handle icmp traffic through the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/31.html" target="_blank"&gt;http://www.cisco.com/warp/public/110/31.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, remember to issue clear xlate after any modifications to ACLs or statics and save with write mem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Dec 2004 10:28:20 GMT</pubDate>
    <dc:creator>jmia</dc:creator>
    <dc:date>2004-12-22T10:28:20Z</dc:date>
    <item>
      <title>Problem passing traffic outside the pix</title>
      <link>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315451#M553404</link>
      <description>&lt;P&gt;I am having an issue where all wanted traffic can get in (Webpages, DNS, SMTP, etc.) but no machine from the inside can get out....even with a ping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attached my config,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to ping to the outside from inside, I get this error logged...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;305006: portmap translation creation failed for icmp src inside:192.168.4.22 dst outside:63.243.97.154 (type 8, code 0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also see this for UDP as well...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be great!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315451#M553404</guid>
      <dc:creator>eelliston</dc:creator>
      <dc:date>2020-02-21T07:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Problem passing traffic outside the pix</title>
      <link>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315452#M553405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eric, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a quick look at your config and one thing I noticed is that you dont't seem to have any access-group LANOut in interface inside applied, also for your reference check out the following URL on how to handle icmp traffic through the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/31.html" target="_blank"&gt;http://www.cisco.com/warp/public/110/31.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, remember to issue clear xlate after any modifications to ACLs or statics and save with write mem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2004 10:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315452#M553405</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2004-12-22T10:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problem passing traffic outside the pix</title>
      <link>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315453#M553406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Humm, in with the acl applied (access-group LANOut in interface inside) and clearing the xlate...same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't ping...can't surf...humm..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2004 13:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315453#M553406</guid>
      <dc:creator>eelliston</dc:creator>
      <dc:date>2004-12-22T13:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problem passing traffic outside the pix</title>
      <link>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315454#M553407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh, and another thing...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The devices on the inside (windows servers) have 2 IPs on the interface.   One is 192.168.4.x the other is 192.168.64.x,192.168.65.x or 192.168.68.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do a translation to that network (one to one)...which seems to work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is when I try to surf outside....the machines primary ip is the 192.168.4.x network, which has a one to many translation (PAT).  I dunno why...the client wanted it this way for some reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe that will help figure out whats up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2004 13:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-passing-traffic-outside-the-pix/m-p/315454#M553407</guid>
      <dc:creator>eelliston</dc:creator>
      <dc:date>2004-12-22T13:57:41Z</dc:date>
    </item>
  </channel>
</rss>

