<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX doesn't allow my LAN to INTERNET in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390001#M555981</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jogillis, I have used capture command on pix and it's showing me some packet captured on the PIX outside of ping from inside laptop to ISP GW IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can experiment if u suggest me the exact syntax of capture command which u wanted me to check....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done "route inside 172.16.20.0 255.255.255.0 10.1.1.1" at PIX but still I am not able to browse Internet from my inside world. I am provided two PUBLIC IP from my ISP i.e.208.144.230.197 and 198.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have removed access-list from my router:&lt;/P&gt;&lt;P&gt;Pls. confirm me that there is no problem at my router or is there any fixup of protocol,access-list are require? I think now I should isolate the problem one by one...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest config:&lt;/P&gt;&lt;P&gt;version 12.3&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname VLANRouter&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 10.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; ip address 172.16.29.1 255.255.255.0&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.1.1.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. clear me 1st router config part. Then we shall move further....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for u support.&lt;/P&gt;&lt;P&gt;Hiren.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Oct 2004 13:18:49 GMT</pubDate>
    <dc:creator>hiruannaofit</dc:creator>
    <dc:date>2004-10-27T13:18:49Z</dc:date>
    <item>
      <title>PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389989#M555964</link>
      <description>&lt;P&gt;Hi dear all,&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Actually I have set "access-list permit icmp any any echo-reply" time-exceeded &amp;amp; unreachable.......so now I am able to ping from my PIX console to my ISP GW ip...but still I am not able to access internet or ping from my inside n/w PCs to internet GW.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Pls. find the below details of my n/w and config.and suggest where am I missing?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I need ur help badly, now it's a question of my output....please help me ASAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't remove my border router because it has been sold to my customers earlier for my SUN servers.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Pls. note my yahoo messenger ID is &lt;A href="mailto:barodians_us@yahoo.com" target="_blank"&gt;barodians_us@yahoo.com&lt;/A&gt; If u are not disturb u can come on yahoo for chatting to suggest me online.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;N/W setup:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;#My router inside ip (172.16.29.1/24)--Router outside (10.1.1.1/24)--PIX inside (10.1.1.2/24)--PIX outside (208.144.230.197 255.255.255.224-ISP supplied)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#My ISP Gateway address is 208.144.230.200&lt;/P&gt;&lt;P&gt;#My DNS servers are 208.144.230.1 and 208.144.230.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#VLAN Config:&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip dhcp conflict logging&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.29.1 172.16.29.240&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.29.250 172.16.29.254&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool dhcppool&lt;/P&gt;&lt;P&gt;   network 172.16.29.0 255.255.255.0&lt;/P&gt;&lt;P&gt;   dns-server 208.144.230.1 208.144.230.2 &lt;/P&gt;&lt;P&gt;   default-router 172.16.29.1 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 208.144.230.197 255.255.255.224&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; ip address 172.16.29.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat inside source list 7 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 208.144.230.200&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 7 permit 172.16.29.0 0.0.0.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#PIX 515E config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname VLANPIX&lt;/P&gt;&lt;P&gt;domain-name VLAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit icmp any any&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq pop3&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq smtp&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq domain&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit udp any any eq domain&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq www&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq telnet&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq h323&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq https&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq 1863&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq ftp-data&lt;/P&gt;&lt;P&gt;access-list acl_outbound permit tcp any any eq ftp&lt;/P&gt;&lt;P&gt;access-list acl_outbound deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit icmp any any&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq 1863&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq ftp&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq ftp-data&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq h323&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq pop3&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq smtp&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq www&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit tcp any any eq domain&lt;/P&gt;&lt;P&gt;access-list acl_inbound permit udp any any eq domain&lt;/P&gt;&lt;P&gt;access-list acl_inbound deny ip any any&lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 208.144.230.197 255.255.255.224&lt;/P&gt;&lt;P&gt;ip address inside 10.1.1.2 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_inbound in interface outside&lt;/P&gt;&lt;P&gt;access-group acl_outbound in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 208.144.230.200 1&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 10.1.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Hiren Mehta&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389989#M555964</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2020-02-21T07:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389990#M555965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hiren,&lt;/P&gt;&lt;P&gt;first of all I miss in your config global IP address.&lt;/P&gt;&lt;P&gt;The other things seem to be O.K.Ping from console has nothing to do with an access-list.&lt;/P&gt;&lt;P&gt;If you try to ping through the PIX,you can watch it&lt;/P&gt;&lt;P&gt;with debug icmp trace.It gives you information,whether the ICMP packets leave PIX and return ICMP packets are coming back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                         Hope it helps&lt;/P&gt;&lt;P&gt;                                       Zdenek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2004 10:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389990#M555965</guid>
      <dc:creator>zroth</dc:creator>
      <dc:date>2004-10-22T10:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389991#M555967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Zdenek, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to receive ur immediate response.&lt;/P&gt;&lt;P&gt;I have put icmp trace on and check from my PIX console that my ping (ICMP) goes from my outside pix to ISP GW address and echo-reply back to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have put "global(outside) 1 interface" i.e.PAT for all. I don't know what to put "global (outside) 1 ip_add netmask x.x.x.x" pls. suggest..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My public ip given by ISP is 208.144.230.198 255.255.255.224"....what could be the "global(outside)"...or how can I get?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope to see u soon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hiren. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2004 11:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389991#M555967</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2004-10-22T11:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389992#M555969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hiren,&lt;/P&gt;&lt;P&gt;most probably you have a wrong address on your router&lt;/P&gt;&lt;P&gt;outside interface.From your config I see it is 208.144.230.197.This is the address of your PIX outside interface.You have to change your router's&lt;/P&gt;&lt;P&gt;outside interface to something from the network 10.1.1.0 255.255.255.0,for instance 10.1.1.1.Then you&lt;/P&gt;&lt;P&gt;should also define default route on your router to&lt;/P&gt;&lt;P&gt;inside PIX interface (10.1.1.2).Both inside PIX interface and outside router interface should be able to ping each other,whixh I presume is not the case now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                          Try it&lt;/P&gt;&lt;P&gt;                                      Zdenek&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2004 12:10:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389992#M555969</guid>
      <dc:creator>zroth</dc:creator>
      <dc:date>2004-10-22T12:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389993#M555970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Zdenek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes..Yes.. ur true on router part. I have changed my Router outside to 10.1.1.1 255.255.255.0 and changed the "ip route 0.0.0.0 0.0.0.0 10.1.1.2". Is these OK..I think my route path set from router outside-to-PIX inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to ping from Router console to PIX inside now. but it gives me "requested time out" from my Laptop(ip set in the range of router insdie) to pix inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though I am able to ping router inside,outside even PIX ICMP trace shows me ping request received and reply sent back to router when I monitor my ping through console. But on laptop ping response is "Requested time out".....am I missing something on router ....Pls. suggest me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hiren &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2004 14:36:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389993#M555970</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2004-10-22T14:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389994#M555971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Are you NAT(ing) from inside to outside on your router? If so, what is the purpose, since your Pix then NAT(s).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2004 18:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389994#M555971</guid>
      <dc:creator>jogillis</dc:creator>
      <dc:date>2004-10-22T18:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389995#M555972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have not most probably route on your laptop to the destination 10.1.1.2 or generally default route over 10.1.1.2.If you ping from your laptop to the inside PIX IP address,you should see incoming ping packets on the PIX.The error is so far in the routing,not in the PIX.Of course,PIX has to know the &lt;/P&gt;&lt;P&gt;route to the source network,it is the route to the inside network of your router.You have to configure it,and I am sure,you win.Try use of debug ip icmp on&lt;/P&gt;&lt;P&gt;router,you will see if your packets reach router and &lt;/P&gt;&lt;P&gt;leave it.So far not bad.&lt;/P&gt;&lt;P&gt;                           Give me a notice&lt;/P&gt;&lt;P&gt;                                   Zdenek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2004 20:18:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389995#M555972</guid>
      <dc:creator>zroth</dc:creator>
      <dc:date>2004-10-22T20:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389996#M555973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure,the NAT on your router should be removed,too.As a whole,PIX overtakes original tasks of router,NAT included.From your laptop with an IP address of inside network 172.16... you must be able to ping inside interface of PIX.And these ping packets should&lt;/P&gt;&lt;P&gt;have original source addresses of 172.16...If you have already changed outside address of the router,ping packets have source address 10.1.1.1.After disabling NAT on the router they should be the original addresses .. 172.16...&lt;/P&gt;&lt;P&gt;In present state should ping actually work,if you have the proper route on your laptop (command route print must show default route over inside int of router].But again,I think you don't need NAT on router anymore.&lt;/P&gt;&lt;P&gt;                           Hope it helps&lt;/P&gt;&lt;P&gt;                                      Zdenek &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Oct 2004 06:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389996#M555973</guid>
      <dc:creator>zroth</dc:creator>
      <dc:date>2004-10-23T06:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389997#M555975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. NAT has been removed from Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting ping from my laptop to PIX inside and reply shows on PIX console that my Laptop IP as a source of this ping....&lt;/P&gt;&lt;P&gt;I have checked on my router that it shows default router is the ip of my router inside (172.16.29.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I ping to PIX inside why on laptop shows "requested timed out" though PIX console shows ICMP request come and ICMP reply to Laptop ip?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not able to receive any ping reply back when I ping from my laptop to PIX outside ..W H Y ????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't used any GLOBAL address....pls. suggest by refering my PIX config...tell me what should be...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used "nat (inside) 1 0 0" on pix and "Global (outside) 1 in interface" (Global address is translated to PAT) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless I am not able to get ping reply from my PIX outside and ISP GW outside I am not able to surf the internet through PIX.....correct...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. suggest....I am very much grateful to u.&lt;/P&gt;&lt;P&gt;Hiren.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Oct 2004 17:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389997#M555975</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2004-10-23T17:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389998#M555977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hiren,&lt;/P&gt;&lt;P&gt;I have my holidays these days,so pls apologize my late.But I promise to help you.&lt;/P&gt;&lt;P&gt;1.Most probably your PIX has not route to the network 172.16.29.0 and is sending ping answer through its default route (outside interface).You&lt;/P&gt;&lt;P&gt;can check it with PIX comand show route.So you must&lt;/P&gt;&lt;P&gt;configure all routes to the networks or hosts,which&lt;/P&gt;&lt;P&gt;are on the inside of the PIX with the command route&lt;/P&gt;&lt;P&gt;- for instance route inside 172.16.29.0 255.255.255.0 10.1.1.1&lt;/P&gt;&lt;P&gt;To ping outside interface of PIX from inside is with PIX impossible,as well you can not ping inside interface from outside.That is PIX firewall.&lt;/P&gt;&lt;P&gt;Your NAT on PIX is O.K.,at least I think so now.&lt;/P&gt;&lt;P&gt;Actually you are doing PAT - all inside addresses are&lt;/P&gt;&lt;P&gt;Translated to the PIX outside address ,which I presume is the only public address you have from your ISP.At present I think you should be able to&lt;/P&gt;&lt;P&gt;ping ISP gateway from laptop - but,not first you haveto define route from PIX to laptop,as written above.&lt;/P&gt;&lt;P&gt;                          Hope it helps.Let me know.&lt;/P&gt;&lt;P&gt;                                  Zdenek &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Oct 2004 10:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389998#M555977</guid>
      <dc:creator>zroth</dc:creator>
      <dc:date>2004-10-25T10:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389999#M555978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;  I agree,  you need a route for the 172.16.29.0 network on your pix,  so he will know how to route the echo reply back to the laptop.  Have you tried using the capture command on any  (all) of the interfaces to see exactly what is happening.  The capture command can be a really big help when trying to trouble shoot problems such as this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Oct 2004 15:18:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/389999#M555978</guid>
      <dc:creator>jogillis</dc:creator>
      <dc:date>2004-10-25T15:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390000#M555980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done "route inside 172.16.20.0 255.255.255.0 10.1.1.1" at PIX but still I am not able to browse Internet from my inside world. I understand the importance of PIX...u are correct.I am provided two PUBLIC IP from my ISP i.e.208.144.230.197 and 198.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have now removed access-list from my router:&lt;/P&gt;&lt;P&gt;Pls. confirm me that there is no problem at my router or is there any fixup of protocol,access-list are require? I think now I should isolate the problem one by one...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest config:&lt;/P&gt;&lt;P&gt;version 12.3&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname VLANRouter&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 10.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; ip address 172.16.29.1 255.255.255.0&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.1.1.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried capture command on PIX also which shows me that some packets of ping from inside to ISP GW are captured on the outside PIX interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. clear me 1st router config part. Then we shall move further....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Zdenek for u support.&lt;/P&gt;&lt;P&gt;Hiren.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2004 13:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390000#M555980</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2004-10-27T13:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390001#M555981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jogillis, I have used capture command on pix and it's showing me some packet captured on the PIX outside of ping from inside laptop to ISP GW IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can experiment if u suggest me the exact syntax of capture command which u wanted me to check....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done "route inside 172.16.20.0 255.255.255.0 10.1.1.1" at PIX but still I am not able to browse Internet from my inside world. I am provided two PUBLIC IP from my ISP i.e.208.144.230.197 and 198.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have removed access-list from my router:&lt;/P&gt;&lt;P&gt;Pls. confirm me that there is no problem at my router or is there any fixup of protocol,access-list are require? I think now I should isolate the problem one by one...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest config:&lt;/P&gt;&lt;P&gt;version 12.3&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname VLANRouter&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 10.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; ip address 172.16.29.1 255.255.255.0&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.1.1.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. clear me 1st router config part. Then we shall move further....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for u support.&lt;/P&gt;&lt;P&gt;Hiren.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2004 13:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390001#M555981</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2004-10-27T13:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390002#M555989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hiren,&lt;/P&gt;&lt;P&gt;in the PIX command route inside 172.16.29.0 etc you possibly made a mistake ( 172.16.20.0 ???).&lt;/P&gt;&lt;P&gt;If this is not the case and you made only the mistake in your message,I think your config is basically a good one.&lt;/P&gt;&lt;P&gt;From your laptop with IP address 172.16.29.x you should be able to ping 172.16.29.1 (inside router's&lt;/P&gt;&lt;P&gt;interface),10.1.1.1 (outside router's interface),10.1.1.2 (inside PIX's interface),208.144.230.200 (ISP GW interface),DNS servers and actually every IP address in Internet,which allows echo-reply.&lt;/P&gt;&lt;P&gt;You won't be able to ping PIX's outside interface.&lt;/P&gt;&lt;P&gt;You can check and watch moving of your ping packets&lt;/P&gt;&lt;P&gt;on your router and on PIX with commands debug icmp trace on PIX and debug ip icmp on the router.You should see your packets leaving and returning your&lt;/P&gt;&lt;P&gt;network.&lt;/P&gt;&lt;P&gt;Two things would be usefull for you .On router and on the PIX you should activate logg with logging buffered command.With command show log you can watch&lt;/P&gt;&lt;P&gt;what happened.With clear logg you can clear the buffer.The second help is to config on the router interfaces ip accounting.With sh ip acco you will be able to watch which packets are leaving router in both directions.Again,with command clear ip acco (interface command!!)you can clear accounting.&lt;/P&gt;&lt;P&gt;Hope it helps.Let me know and good luck.&lt;/P&gt;&lt;P&gt;Command capture you can try later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                             Zdenek &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2004 15:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390002#M555989</guid>
      <dc:creator>zroth</dc:creator>
      <dc:date>2004-10-27T15:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390003#M555990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.Zdenek...My PIX problem is solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did mistake in "route inside" which I corrected but still I was unable to browse but last night I received new activation-key from CISCO through which I have updated my PIX version and whatever u suggested and I configured is damn perfect.......  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my PDM manager is working perfectly and I tested ping...works perfectly....and inside to outside ISP access works with outside to inside attacks blocked..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T H A N K S for ur constant support. Which helps me mostly for the following point:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# Remove NAT on router and set it on PIX&lt;/P&gt;&lt;P&gt;# Show default route (Gateway)at client PC(or laptop)&lt;/P&gt;&lt;P&gt;# Route outside to ISP GW as well as route inside to router IP to be set on PIX&lt;/P&gt;&lt;P&gt;# Debugging commands to trace my ping packets stage by stage&lt;/P&gt;&lt;P&gt;# Importance of global interface, PAT and NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See u. keep in touch. Take good care of urselves.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hiren Mehta.&lt;/P&gt;&lt;P&gt;AFRICA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2004 11:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390003#M555990</guid>
      <dc:creator>hiruannaofit</dc:creator>
      <dc:date>2004-10-29T11:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: PIX doesn't allow my LAN to INTERNET</title>
      <link>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390004#M555991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sorry for the late response but I have been out of the office. Looks like you got the problem solved, congratulations.  As for the capture command, I used it like a packet sniffer. Example&lt;/P&gt;&lt;P&gt;I create an access-list &lt;/P&gt;&lt;P&gt;  "access-list capticmp permit icmp any any"&lt;/P&gt;&lt;P&gt;then I would start a capture&lt;/P&gt;&lt;P&gt; "capture in access-list capticmp interface inside"&lt;/P&gt;&lt;P&gt;       and/or&lt;/P&gt;&lt;P&gt; "capture out access-list capticmp interface outside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Then look at my ping in the capture  to see what is going on with it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2004 16:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-doesn-t-allow-my-lan-to-internet/m-p/390004#M555991</guid>
      <dc:creator>jogillis</dc:creator>
      <dc:date>2004-11-02T16:18:40Z</dc:date>
    </item>
  </channel>
</rss>

