<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic can not ping PIX inside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-not-ping-pix-inside-interface/m-p/43928#M686405</link>
    <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have pix 6.1 firewall in the corporate office,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have pix 3.1 client in the remote network,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup the VPN access,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to connect to the pix from the remote network and be able to ping outside ip address of the PIX,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not able to ping the inside IP address of the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;isakmp policy 8 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 8 encr des&lt;/P&gt;&lt;P&gt;isakmp policy 8 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 8 group 2 &lt;/P&gt;&lt;P&gt;isakmp key "password this you know" address 0.0.0.0 netmask 0.0.0.0&lt;/P&gt;&lt;P&gt;ip local pool amapool 10.10.11.1-10.10.11.254&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 10.0.0.0 255.0.0.0 10.10.11.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 101&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set mytrans esp-des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto dynamic-dynmap 10  set transform-set mytrans&lt;/P&gt;&lt;P&gt;crypto map remote 10 ispec-isakmp dynamic dynmap&lt;/P&gt;&lt;P&gt;vpngroup amaxbot address-pool amapool&lt;/P&gt;&lt;P&gt;vpngroup amaxbot password (this you know)&lt;/P&gt;&lt;P&gt;vpngroup amaxbot idle-time 1800&lt;/P&gt;&lt;P&gt;crypto map remote interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any suggestions,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raul&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 05:57:12 GMT</pubDate>
    <dc:creator>ssvrao</dc:creator>
    <dc:date>2020-02-21T05:57:12Z</dc:date>
    <item>
      <title>can not ping PIX inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-not-ping-pix-inside-interface/m-p/43928#M686405</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have pix 6.1 firewall in the corporate office,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have pix 3.1 client in the remote network,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup the VPN access,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to connect to the pix from the remote network and be able to ping outside ip address of the PIX,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not able to ping the inside IP address of the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;isakmp policy 8 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 8 encr des&lt;/P&gt;&lt;P&gt;isakmp policy 8 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 8 group 2 &lt;/P&gt;&lt;P&gt;isakmp key "password this you know" address 0.0.0.0 netmask 0.0.0.0&lt;/P&gt;&lt;P&gt;ip local pool amapool 10.10.11.1-10.10.11.254&lt;/P&gt;&lt;P&gt;access-list 101 permit ip 10.0.0.0 255.0.0.0 10.10.11.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 101&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set mytrans esp-des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto dynamic-dynmap 10  set transform-set mytrans&lt;/P&gt;&lt;P&gt;crypto map remote 10 ispec-isakmp dynamic dynmap&lt;/P&gt;&lt;P&gt;vpngroup amaxbot address-pool amapool&lt;/P&gt;&lt;P&gt;vpngroup amaxbot password (this you know)&lt;/P&gt;&lt;P&gt;vpngroup amaxbot idle-time 1800&lt;/P&gt;&lt;P&gt;crypto map remote interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any suggestions,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raul&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-ping-pix-inside-interface/m-p/43928#M686405</guid>
      <dc:creator>ssvrao</dc:creator>
      <dc:date>2020-02-21T05:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: can not ping PIX inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-not-ping-pix-inside-interface/m-p/43929#M686416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default you cannot ping the opposite side of the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside users can ping the inside interface  but not the outside and vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although you are coming through a vpn, it is still from  outside and same rules apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also&lt;/P&gt;&lt;P&gt;As you are using the unified client, the wildcard isakmp key line is not required. The client connects using the group name amaxabot and the password specified in the vpngroup statement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2002 12:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-ping-pix-inside-interface/m-p/43929#M686416</guid>
      <dc:creator>turnbull</dc:creator>
      <dc:date>2002-01-15T12:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: can not ping PIX inside interface</title>
      <link>https://community.cisco.com/t5/network-security/can-not-ping-pix-inside-interface/m-p/43930#M686480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to not being able to ping inside interface IP address, I was not able ping any machine which has an IP address in the inside address range of PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words I was not able to ping any machine in their LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I think I have solved it, I have added the manual route to the inside interface in my client, with metric 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I am able to ping machines which are inside the pix interface range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Raul&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2002 19:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-ping-pix-inside-interface/m-p/43930#M686480</guid>
      <dc:creator>ssvrao</dc:creator>
      <dc:date>2002-01-15T19:58:34Z</dc:date>
    </item>
  </channel>
</rss>

