<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 515 won't Ping in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-won-t-ping/m-p/25030#M680485</link>
    <description>&lt;P&gt;I've setup a PIX 515UR as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet--Proxy--Hub---PIX515UR---HUB---Host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't ping from the host to the Proxy.  I also can't ping from the Proxy to the host.  I believe I've correctly set the access-lists and access-groups according to the documentation.  I can Ping the outside and inside interfaces from the outside and inside, but I cannot Ping through the 515UR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.1(1)&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 intf2 security10&lt;/P&gt;&lt;P&gt;nameif ethernet3 intf3 security15&lt;/P&gt;&lt;P&gt;nameif ethernet4 intf4 security20&lt;/P&gt;&lt;P&gt;nameif ethernet5 intf5 security25&lt;/P&gt;&lt;P&gt;enable password b1bl7I8rH9BR1W9D encrypted&lt;/P&gt;&lt;P&gt;passwd yruhere99yruhere encrypted&lt;/P&gt;&lt;P&gt;hostname xxxxxxxxx&lt;/P&gt;&lt;P&gt;domain-name xxxxxxx.com&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol h323 1720&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list ping_acl permit icmp any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging buffered debugging&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;interface ethernet2 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet3 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet4 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet5 auto shutdown&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply inside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu intf2 1500&lt;/P&gt;&lt;P&gt;mtu intf3 1500&lt;/P&gt;&lt;P&gt;mtu intf4 1500&lt;/P&gt;&lt;P&gt;mtu intf5 1500&lt;/P&gt;&lt;P&gt;ip address outside 192.168.1.104 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside xxx.xxx.14.1 255.255.255.xxx&lt;/P&gt;&lt;P&gt;ip address intf2 127.0.0.1 255.255.255.255&lt;/P&gt;&lt;P&gt;ip address intf3 127.0.0.1 255.255.255.255&lt;/P&gt;&lt;P&gt;ip address intf4 127.0.0.1 255.255.255.255&lt;/P&gt;&lt;P&gt;ip address intf5 127.0.0.1 255.255.255.255&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;failover poll 15&lt;/P&gt;&lt;P&gt;failover ip address outside 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address inside 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address intf2 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address intf3 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address intf4 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address intf5 0.0.0.0&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat (inside) 0 xxx.xxx.14.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) xxx.xxx.14.0 161.157.14.0 netmask 255.255.255.xxx 0 0&lt;/P&gt;&lt;P&gt;access-group ping_acl in interface outside&lt;/P&gt;&lt;P&gt;access-group ping_acl in interface inside&lt;/P&gt;&lt;P&gt;conduit permit tcp any any&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si&lt;/P&gt;&lt;P&gt;p 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http xxx.xxx.xxx.13 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;http xxx.xxx.xxx.13 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;no sysopt route dnat&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:57e9beab1b2643898e2ff8c71d41726c&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;[OK]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 05:53:31 GMT</pubDate>
    <dc:creator>chonet4444</dc:creator>
    <dc:date>2020-02-21T05:53:31Z</dc:date>
    <item>
      <title>PIX 515 won't Ping</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-won-t-ping/m-p/25030#M680485</link>
      <description>&lt;P&gt;I've setup a PIX 515UR as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet--Proxy--Hub---PIX515UR---HUB---Host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't ping from the host to the Proxy.  I also can't ping from the Proxy to the host.  I believe I've correctly set the access-lists and access-groups according to the documentation.  I can Ping the outside and inside interfaces from the outside and inside, but I cannot Ping through the 515UR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.1(1)&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 intf2 security10&lt;/P&gt;&lt;P&gt;nameif ethernet3 intf3 security15&lt;/P&gt;&lt;P&gt;nameif ethernet4 intf4 security20&lt;/P&gt;&lt;P&gt;nameif ethernet5 intf5 security25&lt;/P&gt;&lt;P&gt;enable password b1bl7I8rH9BR1W9D encrypted&lt;/P&gt;&lt;P&gt;passwd yruhere99yruhere encrypted&lt;/P&gt;&lt;P&gt;hostname xxxxxxxxx&lt;/P&gt;&lt;P&gt;domain-name xxxxxxx.com&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol h323 1720&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list ping_acl permit icmp any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging buffered debugging&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;interface ethernet2 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet3 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet4 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet5 auto shutdown&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply inside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu intf2 1500&lt;/P&gt;&lt;P&gt;mtu intf3 1500&lt;/P&gt;&lt;P&gt;mtu intf4 1500&lt;/P&gt;&lt;P&gt;mtu intf5 1500&lt;/P&gt;&lt;P&gt;ip address outside 192.168.1.104 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside xxx.xxx.14.1 255.255.255.xxx&lt;/P&gt;&lt;P&gt;ip address intf2 127.0.0.1 255.255.255.255&lt;/P&gt;&lt;P&gt;ip address intf3 127.0.0.1 255.255.255.255&lt;/P&gt;&lt;P&gt;ip address intf4 127.0.0.1 255.255.255.255&lt;/P&gt;&lt;P&gt;ip address intf5 127.0.0.1 255.255.255.255&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;failover poll 15&lt;/P&gt;&lt;P&gt;failover ip address outside 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address inside 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address intf2 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address intf3 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address intf4 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address intf5 0.0.0.0&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat (inside) 0 xxx.xxx.14.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) xxx.xxx.14.0 161.157.14.0 netmask 255.255.255.xxx 0 0&lt;/P&gt;&lt;P&gt;access-group ping_acl in interface outside&lt;/P&gt;&lt;P&gt;access-group ping_acl in interface inside&lt;/P&gt;&lt;P&gt;conduit permit tcp any any&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si&lt;/P&gt;&lt;P&gt;p 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http xxx.xxx.xxx.13 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;http xxx.xxx.xxx.13 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;no sysopt route dnat&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:57e9beab1b2643898e2ff8c71d41726c&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;[OK]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-won-t-ping/m-p/25030#M680485</guid>
      <dc:creator>chonet4444</dc:creator>
      <dc:date>2020-02-21T05:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 won't Ping</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-won-t-ping/m-p/25031#M680487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list acl_out permit icmp any any&lt;/P&gt;&lt;P&gt;access-list acl_out permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list acl_out permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list acl_out permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dont need to apply the statement to the inside interface, remeber there is an implict deny after a permit statement!!  You will be able to ping from the inside host but not from the outside in!  hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2001 01:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-won-t-ping/m-p/25031#M680487</guid>
      <dc:creator>jgmitter</dc:creator>
      <dc:date>2001-11-01T01:15:21Z</dc:date>
    </item>
  </channel>
</rss>

