<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 881G Router is unable to ping from the LAN side.  Any help? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353418#M856863</link>
    <description>&lt;P&gt;Here is my configuration.&amp;nbsp;&amp;nbsp; I can ping from the Router out to the internet.&amp;nbsp; From the LAN I can ping the "inside" port and the "outside" port, but nothing past that.&amp;nbsp; I also have no other access (web, smtp, etc).&amp;nbsp; I am new to this device and zone based firewall, any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;abc-FW#sho run&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 6238 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.4&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname abc-FW&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;logging message-counter syslog&lt;BR /&gt;logging buffered 51200 warnings&lt;BR /&gt;enable secret 5 $2$ABC1234AC88394DD&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;memory-size iomem 10&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-1348925195&lt;BR /&gt; enrollment selfsigned&lt;BR /&gt; subject-name cn=IOS-Self-Signed-Certificate-1348925195&lt;BR /&gt; revocation-check none&lt;BR /&gt; rsakeypair TP-self-signed-1348925195&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-1348925195&lt;BR /&gt; certificate self-signed 01&lt;BR /&gt;&amp;nbsp; 3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030 &lt;BR /&gt;&amp;nbsp; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 &lt;BR /&gt;&amp;nbsp; 69666963 6174652D 31333438 39323531 3935301E 170D3130 30343133 31373532 &lt;BR /&gt;&amp;nbsp; 33395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 &lt;BR /&gt;&amp;nbsp; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 33343839 &lt;BR /&gt;&amp;nbsp; 32353139 3530819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 &lt;BR /&gt;&amp;nbsp; 81009327 F5DF6233 33F6BDBB 6BB6CFEB 7B24FBE5 C5DC8C3F 36CFAF7C D38A0C33 &lt;BR /&gt;&amp;nbsp; 5974599B 05535C75 0F4969DF 77BED34F 127B0A4A 830CAA03 62F8F74A 6AC2BAB6 &lt;BR /&gt;&amp;nbsp; 6B3C9588 E9619EC9 C400CBBA 2C633833 79EF3B6A 929DA9A7 72397C2D 8CBE4742 &lt;BR /&gt;&amp;nbsp; 285E31B8 83ED76AB 10BD910A AB2C3C3C 0DEFAD68 C9695CB5 E2EC09F1 2DAD4293 &lt;BR /&gt;&amp;nbsp; 70490203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603 &lt;BR /&gt;&amp;nbsp; 551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D &lt;BR /&gt;&amp;nbsp; 301F0603 551D2304 18301680 14A98572 63934412 FDC7D679 7D454AD8 28BD04CB &lt;BR /&gt;&amp;nbsp; A1301D06 03551D0E 04160414 A9857263 934412FD C7D6797D 454AD828 BD04CBA1 &lt;BR /&gt;&amp;nbsp; 300D0609 2A864886 F70D0101 04050003 81810057 BA03D487 50C320B1 85280394 &lt;BR /&gt;&amp;nbsp; A1676BD1 90CC7C58 C5CF5291 D7EAA591 8608AB1D F7B526CC 8B2C5AD4 5FF03BBA &lt;BR /&gt;&amp;nbsp; E02519C4 C178A97D 959919A2 3215AE93 20B1BF1E 05D2835A 3A4144EB 4F3BD335 &lt;BR /&gt;&amp;nbsp; 321A8B6C 3FDC4311 611575A3 5BE7DB11 02807F28 75C9AA31 28B5B540 DA11C546 &lt;BR /&gt;&amp;nbsp; 36E82DA6 8954831B F945A0DA 6FEED096 E35D83&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; quit&lt;BR /&gt;ip source-route&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip dhcp excluded-address 10.10.10.1&lt;BR /&gt;ip dhcp excluded-address 10.10.10.51 10.10.10.254&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool ccp-pool&lt;BR /&gt;&amp;nbsp;&amp;nbsp; import all&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.10.10.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.10.10.1 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; dns-server 4.2.2.4 4.2.2.3 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; lease 0 2&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;ip domain name abcDist.com&lt;BR /&gt;ip name-server 4.2.2.4&lt;BR /&gt;ip name-server 4.2.2.3&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;username admin123 privilege 15 secret 5 xxxxxyzzyxxxx&lt;BR /&gt;! &lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;archive&lt;BR /&gt; log config&lt;BR /&gt;&amp;nbsp; hidekeys&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map type inspect match-any ccp-cls-insp-traffic&lt;BR /&gt; match protocol cuseeme&lt;BR /&gt; match protocol dns&lt;BR /&gt; match protocol ftp&lt;BR /&gt; match protocol h323&lt;BR /&gt; match protocol https&lt;BR /&gt; match protocol icmp&lt;BR /&gt; match protocol imap&lt;BR /&gt; match protocol pop3&lt;BR /&gt; match protocol netshow&lt;BR /&gt; match protocol shell&lt;BR /&gt; match protocol realmedia&lt;BR /&gt; match protocol rtsp&lt;BR /&gt; match protocol smtp extended&lt;BR /&gt; match protocol sql-net&lt;BR /&gt; match protocol streamworks&lt;BR /&gt; match protocol tftp&lt;BR /&gt; match protocol vdolive&lt;BR /&gt; match protocol tcp&lt;BR /&gt; match protocol udp&lt;BR /&gt;class-map type inspect match-all ccp-insp-traffic&lt;BR /&gt; match class-map ccp-cls-insp-traffic&lt;BR /&gt;class-map type inspect match-any ccp-cls-icmp-access&lt;BR /&gt; match protocol icmp&lt;BR /&gt; match protocol tcp&lt;BR /&gt; match protocol udp&lt;BR /&gt;class-map type inspect match-any in-out&lt;BR /&gt; match access-group 110&lt;BR /&gt; match protocol icmp&lt;BR /&gt; match protocol smtp&lt;BR /&gt; match protocol https&lt;BR /&gt; match protocol dns&lt;BR /&gt; match protocol http&lt;BR /&gt;class-map type inspect match-all ccp-invalid-src&lt;BR /&gt; match access-group 100&lt;BR /&gt;class-map type inspect match-all ccp-icmp-access&lt;BR /&gt; match class-map ccp-cls-icmp-access&lt;BR /&gt;class-map type inspect match-all ccp-protocol-http&lt;BR /&gt; match protocol http&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect ccp-permit-icmpreply&lt;BR /&gt; class type inspect ccp-icmp-access&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;policy-map type inspect ccp-inspect&lt;BR /&gt; class type inspect ccp-invalid-src&lt;BR /&gt;&amp;nbsp; drop log&lt;BR /&gt; class type inspect ccp-protocol-http&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt; class type inspect ccp-insp-traffic&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; drop&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;policy-map type inspect outbound-policy&lt;BR /&gt; class type inspect in-out&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect ccp-permit&lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;!&lt;BR /&gt;zone security out-zone&lt;BR /&gt;zone security in-zone&lt;BR /&gt;zone-pair security ccp-zp-self-out source self destination out-zone&lt;BR /&gt; service-policy type inspect ccp-permit-icmpreply&lt;BR /&gt;zone-pair security ccp-zp-in-out source in-zone destination out-zone&lt;BR /&gt; service-policy type inspect outbound-policy&lt;BR /&gt;zone-pair security ccp-zp-out-self source out-zone destination self&lt;BR /&gt; service-policy type inspect ccp-permit&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet1&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet2&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet3&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet4&lt;BR /&gt; description $FW_OUTSIDE$$ES_WAN$&lt;BR /&gt; ip address dhcp client-id FastEthernet4&lt;BR /&gt; zone-member security out-zone&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt;!&lt;BR /&gt;interface Cellular0&lt;BR /&gt; no ip address&lt;BR /&gt; encapsulation ppp&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$&lt;BR /&gt; ip address 10.10.10.1 255.255.255.0&lt;BR /&gt; zone-member security in-zone&lt;BR /&gt; ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;ip http server&lt;BR /&gt;ip http access-class 23&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;access-list 100 remark CCP_ACL Category=128&lt;BR /&gt;access-list 100 permit ip host 255.255.255.255 any&lt;BR /&gt;access-list 100 permit ip 127.0.0.0 0.255.255.255 any&lt;BR /&gt;access-list 110 permit tcp any any eq www&lt;BR /&gt;access-list 110 permit icmp any any&lt;BR /&gt;access-list 110 permit tcp any any&lt;BR /&gt;access-list 110 permit udp any any&lt;BR /&gt;access-list 110 permit gre any any&lt;BR /&gt;no cdp run&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; login local&lt;BR /&gt; no modem enable&lt;BR /&gt;line aux 0&lt;BR /&gt;line 3&lt;BR /&gt; no exec&lt;BR /&gt;line 4&lt;BR /&gt; exec-timeout 0 0&lt;BR /&gt; timeout login response 0&lt;BR /&gt; privilege level 0&lt;BR /&gt; modem answer-timeout 0&lt;BR /&gt; modem dtr-delay 0&lt;BR /&gt; activation-character 0&lt;BR /&gt; data-character-bits 8&lt;BR /&gt; exec-character-bits 8&lt;BR /&gt; special-character-bits 8&lt;BR /&gt; no exec&lt;BR /&gt; length 0&lt;BR /&gt; width 0&lt;BR /&gt; no history&lt;BR /&gt; no editing&lt;BR /&gt; transport preferred none&lt;BR /&gt; transport input none&lt;BR /&gt; transport output none&lt;BR /&gt; escape-character soft 0&lt;BR /&gt; escape-character 0&lt;BR /&gt; no ip tcp input-coalesce-threshold&lt;BR /&gt; callback forced-wait 0&lt;BR /&gt; callback nodsr-wait 0&lt;BR /&gt; stopbits 1&lt;BR /&gt; speed 115000&lt;BR /&gt;line vty 0 4&lt;BR /&gt; access-class 23 in&lt;BR /&gt; privilege level 15&lt;BR /&gt; login local&lt;BR /&gt; transport input telnet ssh&lt;BR /&gt;!&lt;BR /&gt;scheduler max-task-time 5000&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;abc-FW#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:32:34 GMT</pubDate>
    <dc:creator>Richard Baker</dc:creator>
    <dc:date>2019-03-11T17:32:34Z</dc:date>
    <item>
      <title>881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353418#M856863</link>
      <description>&lt;P&gt;Here is my configuration.&amp;nbsp;&amp;nbsp; I can ping from the Router out to the internet.&amp;nbsp; From the LAN I can ping the "inside" port and the "outside" port, but nothing past that.&amp;nbsp; I also have no other access (web, smtp, etc).&amp;nbsp; I am new to this device and zone based firewall, any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;abc-FW#sho run&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 6238 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.4&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname abc-FW&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;logging message-counter syslog&lt;BR /&gt;logging buffered 51200 warnings&lt;BR /&gt;enable secret 5 $2$ABC1234AC88394DD&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;memory-size iomem 10&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-1348925195&lt;BR /&gt; enrollment selfsigned&lt;BR /&gt; subject-name cn=IOS-Self-Signed-Certificate-1348925195&lt;BR /&gt; revocation-check none&lt;BR /&gt; rsakeypair TP-self-signed-1348925195&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-1348925195&lt;BR /&gt; certificate self-signed 01&lt;BR /&gt;&amp;nbsp; 3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030 &lt;BR /&gt;&amp;nbsp; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 &lt;BR /&gt;&amp;nbsp; 69666963 6174652D 31333438 39323531 3935301E 170D3130 30343133 31373532 &lt;BR /&gt;&amp;nbsp; 33395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 &lt;BR /&gt;&amp;nbsp; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 33343839 &lt;BR /&gt;&amp;nbsp; 32353139 3530819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 &lt;BR /&gt;&amp;nbsp; 81009327 F5DF6233 33F6BDBB 6BB6CFEB 7B24FBE5 C5DC8C3F 36CFAF7C D38A0C33 &lt;BR /&gt;&amp;nbsp; 5974599B 05535C75 0F4969DF 77BED34F 127B0A4A 830CAA03 62F8F74A 6AC2BAB6 &lt;BR /&gt;&amp;nbsp; 6B3C9588 E9619EC9 C400CBBA 2C633833 79EF3B6A 929DA9A7 72397C2D 8CBE4742 &lt;BR /&gt;&amp;nbsp; 285E31B8 83ED76AB 10BD910A AB2C3C3C 0DEFAD68 C9695CB5 E2EC09F1 2DAD4293 &lt;BR /&gt;&amp;nbsp; 70490203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603 &lt;BR /&gt;&amp;nbsp; 551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D &lt;BR /&gt;&amp;nbsp; 301F0603 551D2304 18301680 14A98572 63934412 FDC7D679 7D454AD8 28BD04CB &lt;BR /&gt;&amp;nbsp; A1301D06 03551D0E 04160414 A9857263 934412FD C7D6797D 454AD828 BD04CBA1 &lt;BR /&gt;&amp;nbsp; 300D0609 2A864886 F70D0101 04050003 81810057 BA03D487 50C320B1 85280394 &lt;BR /&gt;&amp;nbsp; A1676BD1 90CC7C58 C5CF5291 D7EAA591 8608AB1D F7B526CC 8B2C5AD4 5FF03BBA &lt;BR /&gt;&amp;nbsp; E02519C4 C178A97D 959919A2 3215AE93 20B1BF1E 05D2835A 3A4144EB 4F3BD335 &lt;BR /&gt;&amp;nbsp; 321A8B6C 3FDC4311 611575A3 5BE7DB11 02807F28 75C9AA31 28B5B540 DA11C546 &lt;BR /&gt;&amp;nbsp; 36E82DA6 8954831B F945A0DA 6FEED096 E35D83&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; quit&lt;BR /&gt;ip source-route&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip dhcp excluded-address 10.10.10.1&lt;BR /&gt;ip dhcp excluded-address 10.10.10.51 10.10.10.254&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool ccp-pool&lt;BR /&gt;&amp;nbsp;&amp;nbsp; import all&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.10.10.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.10.10.1 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; dns-server 4.2.2.4 4.2.2.3 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; lease 0 2&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;ip domain name abcDist.com&lt;BR /&gt;ip name-server 4.2.2.4&lt;BR /&gt;ip name-server 4.2.2.3&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;username admin123 privilege 15 secret 5 xxxxxyzzyxxxx&lt;BR /&gt;! &lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;archive&lt;BR /&gt; log config&lt;BR /&gt;&amp;nbsp; hidekeys&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map type inspect match-any ccp-cls-insp-traffic&lt;BR /&gt; match protocol cuseeme&lt;BR /&gt; match protocol dns&lt;BR /&gt; match protocol ftp&lt;BR /&gt; match protocol h323&lt;BR /&gt; match protocol https&lt;BR /&gt; match protocol icmp&lt;BR /&gt; match protocol imap&lt;BR /&gt; match protocol pop3&lt;BR /&gt; match protocol netshow&lt;BR /&gt; match protocol shell&lt;BR /&gt; match protocol realmedia&lt;BR /&gt; match protocol rtsp&lt;BR /&gt; match protocol smtp extended&lt;BR /&gt; match protocol sql-net&lt;BR /&gt; match protocol streamworks&lt;BR /&gt; match protocol tftp&lt;BR /&gt; match protocol vdolive&lt;BR /&gt; match protocol tcp&lt;BR /&gt; match protocol udp&lt;BR /&gt;class-map type inspect match-all ccp-insp-traffic&lt;BR /&gt; match class-map ccp-cls-insp-traffic&lt;BR /&gt;class-map type inspect match-any ccp-cls-icmp-access&lt;BR /&gt; match protocol icmp&lt;BR /&gt; match protocol tcp&lt;BR /&gt; match protocol udp&lt;BR /&gt;class-map type inspect match-any in-out&lt;BR /&gt; match access-group 110&lt;BR /&gt; match protocol icmp&lt;BR /&gt; match protocol smtp&lt;BR /&gt; match protocol https&lt;BR /&gt; match protocol dns&lt;BR /&gt; match protocol http&lt;BR /&gt;class-map type inspect match-all ccp-invalid-src&lt;BR /&gt; match access-group 100&lt;BR /&gt;class-map type inspect match-all ccp-icmp-access&lt;BR /&gt; match class-map ccp-cls-icmp-access&lt;BR /&gt;class-map type inspect match-all ccp-protocol-http&lt;BR /&gt; match protocol http&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect ccp-permit-icmpreply&lt;BR /&gt; class type inspect ccp-icmp-access&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;policy-map type inspect ccp-inspect&lt;BR /&gt; class type inspect ccp-invalid-src&lt;BR /&gt;&amp;nbsp; drop log&lt;BR /&gt; class type inspect ccp-protocol-http&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt; class type inspect ccp-insp-traffic&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; drop&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;policy-map type inspect outbound-policy&lt;BR /&gt; class type inspect in-out&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect ccp-permit&lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;!&lt;BR /&gt;zone security out-zone&lt;BR /&gt;zone security in-zone&lt;BR /&gt;zone-pair security ccp-zp-self-out source self destination out-zone&lt;BR /&gt; service-policy type inspect ccp-permit-icmpreply&lt;BR /&gt;zone-pair security ccp-zp-in-out source in-zone destination out-zone&lt;BR /&gt; service-policy type inspect outbound-policy&lt;BR /&gt;zone-pair security ccp-zp-out-self source out-zone destination self&lt;BR /&gt; service-policy type inspect ccp-permit&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet1&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet2&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet3&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet4&lt;BR /&gt; description $FW_OUTSIDE$$ES_WAN$&lt;BR /&gt; ip address dhcp client-id FastEthernet4&lt;BR /&gt; zone-member security out-zone&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt;!&lt;BR /&gt;interface Cellular0&lt;BR /&gt; no ip address&lt;BR /&gt; encapsulation ppp&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$&lt;BR /&gt; ip address 10.10.10.1 255.255.255.0&lt;BR /&gt; zone-member security in-zone&lt;BR /&gt; ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;ip http server&lt;BR /&gt;ip http access-class 23&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;access-list 100 remark CCP_ACL Category=128&lt;BR /&gt;access-list 100 permit ip host 255.255.255.255 any&lt;BR /&gt;access-list 100 permit ip 127.0.0.0 0.255.255.255 any&lt;BR /&gt;access-list 110 permit tcp any any eq www&lt;BR /&gt;access-list 110 permit icmp any any&lt;BR /&gt;access-list 110 permit tcp any any&lt;BR /&gt;access-list 110 permit udp any any&lt;BR /&gt;access-list 110 permit gre any any&lt;BR /&gt;no cdp run&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; login local&lt;BR /&gt; no modem enable&lt;BR /&gt;line aux 0&lt;BR /&gt;line 3&lt;BR /&gt; no exec&lt;BR /&gt;line 4&lt;BR /&gt; exec-timeout 0 0&lt;BR /&gt; timeout login response 0&lt;BR /&gt; privilege level 0&lt;BR /&gt; modem answer-timeout 0&lt;BR /&gt; modem dtr-delay 0&lt;BR /&gt; activation-character 0&lt;BR /&gt; data-character-bits 8&lt;BR /&gt; exec-character-bits 8&lt;BR /&gt; special-character-bits 8&lt;BR /&gt; no exec&lt;BR /&gt; length 0&lt;BR /&gt; width 0&lt;BR /&gt; no history&lt;BR /&gt; no editing&lt;BR /&gt; transport preferred none&lt;BR /&gt; transport input none&lt;BR /&gt; transport output none&lt;BR /&gt; escape-character soft 0&lt;BR /&gt; escape-character 0&lt;BR /&gt; no ip tcp input-coalesce-threshold&lt;BR /&gt; callback forced-wait 0&lt;BR /&gt; callback nodsr-wait 0&lt;BR /&gt; stopbits 1&lt;BR /&gt; speed 115000&lt;BR /&gt;line vty 0 4&lt;BR /&gt; access-class 23 in&lt;BR /&gt; privilege level 15&lt;BR /&gt; login local&lt;BR /&gt; transport input telnet ssh&lt;BR /&gt;!&lt;BR /&gt;scheduler max-task-time 5000&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;abc-FW#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353418#M856863</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2019-03-11T17:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353419#M856865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're tying to access the Internet and this is your Internet router this makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router will have a public IP (that's why you can PING the Internet from the router).&lt;/P&gt;&lt;P&gt;The router has no NAT configuration, that's why you're not getting past the default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this your situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353419#M856865</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-13T19:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353420#M856867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It currently sits inside a corporate network, thus the reason why it has a private ip on the WAN side.&amp;nbsp; I currently have one in the field that is behind an Internet router (ISP provided).&amp;nbsp; It too has a private IP on the WAN side which is set by DHCP (MAC reserved) from the Internet router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also tried with NAT on and NAT off, same results both time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353420#M856867</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-13T19:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353421#M856868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're saying VLAN1 10.10.10.0/24 is the LAN side correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WAN side is interface fast4 correct?&lt;BR /&gt;I don't see the IP since from the config file since it's getting ip from DHCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The LAN clients should have a default gateway pointing to the 10.10.10.1 so they can pass through the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:54:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353421#M856868</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-13T19:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353422#M856870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct VLAN1 is the inside at 10.10.10.0/24&lt;/P&gt;&lt;P&gt;the outside&amp;nbsp; FE4 is currently set to 192.168.1.115/24&amp;nbsp; GW 192.168.1.231&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP:&amp;nbsp; 10.10.10.2 (DHCP from router)&lt;/P&gt;&lt;P&gt;GW: 10.10.10.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353422#M856870</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-13T19:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353423#M856872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The inside LAN should have a default gateway pointing to the router 10.10.10.1, is it done already?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you source a PING from the LAN's router IP (ping destination_IP source 10.10.10.1) does it succeeds?&lt;/P&gt;&lt;P&gt;What's the IP that you're trying to reach?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353423#M856872</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-13T19:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353424#M856874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the PC I can ping 10.10.10.1 (LAN) and 192.168.1.115 (WAN) but no where else on the other side of the router.&lt;/P&gt;&lt;P&gt;From the Router I can ping everywhere.&amp;nbsp; I used 4.2.2.4 as my test ping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 20:01:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353424#M856874</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-13T20:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353425#M856876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Again, is 10.10.10.1 the default gateway for the LAN subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 20:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353425#M856876</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-13T20:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353426#M856878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, 10.10.10.1 is the default gateway for the LAN subnet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 20:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353426#M856878</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-13T20:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353427#M856881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're using ZBF and let's see if that's not allowing communication between the interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For a test do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface fast4&lt;BR /&gt;no zone-member security out-zone&lt;/P&gt;&lt;P&gt;interface vlan1&lt;BR /&gt;no zone-member security in-zone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 20:09:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353427#M856881</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-13T20:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353428#M856884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;removed them both, still unable to ping out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 20:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353428#M856884</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-13T20:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353429#M856886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If from the router itself you can PING 4.2.2.2, then you should be able to source that PING from 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the following:&lt;/P&gt;&lt;P&gt;Enter those commands again and type the following on the router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping 4.2.2.2 source 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it does not work, do a traceroute to see where the packets die.&lt;/P&gt;&lt;P&gt;I think that maybe the router doing NAT, is not doing NAT for the 10.10.10.0/24 network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 21:03:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353429#M856886</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-13T21:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353430#M856888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried pinging from inside the router, was successful, tried ping 4.2.2.2 source 10.10.10.1&amp;nbsp; received 5 timeouts.&amp;nbsp; Did the trace route and got the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;abc-FW#traceroute 4.2.2.2&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to vnsc-bak.sys.gtei.net (4.2.2.2)&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1 192.168.1.250 4 msec 0 msec 4 msec&lt;BR /&gt;&amp;nbsp; 2 host-193-145-x-x.ussignalcom.net (x.x.145.193) 12 msec 12 msec 16 msec&lt;BR /&gt;&amp;nbsp; 3 te4-0-0.pe02.ind.ussignalcom.net (x.204.127.250) 28 msec 32 msec 36 msec&lt;BR /&gt;&amp;nbsp; 4 te7-0-0.pe01.sbn.ussignalcom.net (x.204.127.101) 32 msec 28 msec 28 msec&lt;BR /&gt;&amp;nbsp; 5 te4-0-1.pe02.grr.ussignalcom.net (x.204.127.229) 28 msec 28 msec 32 msec&lt;BR /&gt;&amp;nbsp; 6 te1-0-0.pe01.dtw.ussignalcom.net (x.204.127.254) 32 msec 28 msec 28 msec&lt;BR /&gt;&amp;nbsp; 7 ge-6-11-137.car2.Detroit1.Level3.net (4.79.12.9) 28 msec 24 msec 32 msec&lt;BR /&gt;&amp;nbsp; 8 ae-11-11.car1.Detroit1.Level3.net (4.69.133.245) 24 msec 28 msec 36 msec&lt;BR /&gt;&amp;nbsp; 9 ae-8-8.ebr2.Chicago1.Level3.net (4.69.133.242) 44 msec 40 msec 36 msec&lt;BR /&gt; 10 ae-21-52.car1.Chicago1.Level3.net (4.68.101.34) 44 msec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ae-21-54.car1.Chicago1.Level3.net (4.68.101.98) 32 msec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ae-21-56.car1.Chicago1.Level3.net (4.68.101.162) 32 msec&lt;BR /&gt; 11 vnsc-bak.sys.gtei.net (4.2.2.2) 44 msec 32 msec 36 msec&lt;BR /&gt;abc-FW#traceroute 4.2.2.2 source 10.10.10.1&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to vnsc-bak.sys.gtei.net (4.2.2.2)&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp; *&amp;nbsp; *&amp;nbsp; * &lt;BR /&gt;&amp;nbsp; 2&amp;nbsp; *&amp;nbsp; *&amp;nbsp; * &lt;BR /&gt;&amp;nbsp; 3&amp;nbsp; *&amp;nbsp; *&amp;nbsp; * &lt;BR /&gt;&amp;nbsp; 4&amp;nbsp; *&amp;nbsp; *&amp;nbsp; * &lt;BR /&gt;&amp;nbsp; 5&amp;nbsp; *&amp;nbsp; *&amp;nbsp; * &lt;BR /&gt;~ &lt;/P&gt;&lt;P&gt; 29&amp;nbsp; *&amp;nbsp; *&amp;nbsp; * &lt;BR /&gt; 30&amp;nbsp; *&amp;nbsp; *&amp;nbsp; * &lt;BR /&gt;abc-FW#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also setup NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet4&lt;BR /&gt; description $FW_OUTSIDE$$ES_WAN$&lt;BR /&gt; ip address dhcp client-id FastEthernet4&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt;!&lt;BR /&gt;interface Cellular0&lt;BR /&gt; no ip address&lt;BR /&gt; encapsulation ppp&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$&lt;BR /&gt; ip address 10.10.10.1 255.255.255.0&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt; ip tcp adjust-mss 1452&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Apr 2010 15:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353430#M856888</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-14T15:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353431#M856891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need NAT on this router if it has a private IP being received by DHCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a simple snapshot of the topology that you can post?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Apr 2010 16:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353431#M856891</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-14T16:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353432#M856893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a JPEG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Apr 2010 16:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353432#M856893</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-14T16:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353433#M856895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so from the internal machines, can you PING 1.231 (which is the internet device)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the PING is not succesful, then let's check where it dies by doing a traceroute from the machine to that IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Apr 2010 16:19:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353433#M856895</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-14T16:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353434#M856897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pinging 4.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the 192.168.1.0/24 network we are good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;ping 4.2.2.2&lt;/P&gt;&lt;P&gt;Pinging 4.2.2.2 with 32 bytes of data:&lt;BR /&gt;Reply from 4.2.2.2: bytes=32 time=34ms TTL=53&lt;BR /&gt;Reply from 4.2.2.2: bytes=32 time=32ms TTL=53&lt;BR /&gt;Reply from 4.2.2.2: bytes=32 time=31ms TTL=53&lt;BR /&gt;Reply from 4.2.2.2: bytes=32 time=32ms TTL=53&lt;/P&gt;&lt;P&gt;Ping statistics for 4.2.2.2:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),&lt;BR /&gt;Approximate round trip times in milli-seconds:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Minimum = 31ms, Maximum = 34ms, Average = 32ms&lt;/P&gt;&lt;P&gt;C:\&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the 881G Router we are good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;abc-FW#ping 4.2.2.2&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 4.2.2.2, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 32/33/36 ms&lt;BR /&gt;abc-FW#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the 881G Router with a source of 10.10.10.1 (VLAN1 IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;abc-FW#ping 4.2.2.2 source 10.10.10.1&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 4.2.2.2, timeout is 2 seconds:&lt;BR /&gt;Packet sent with a source address of 10.10.10.1 &lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;BR /&gt;abc-FW#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the 10.10.10.0/24 network no good. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ethernet adapter Local Area Connection:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Connection-specific DNS Suffix&amp;nbsp; . : abc.com&lt;BR /&gt;&amp;nbsp;&amp;nbsp; IPv4 Address. . . . . . . . . . . : 10.10.10.2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Subnet Mask . . . . . . . . . . . : 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Default Gateway . . . . . . . . . : 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;ping 4.2.2.2&lt;/P&gt;&lt;P&gt;Pinging 4.2.2.2 with 32 bytes of data:&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;/P&gt;&lt;P&gt;Ping statistics for 4.2.2.2:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),&lt;/P&gt;&lt;P&gt;C:\&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;tracert 4.2.2.2&lt;/P&gt;&lt;P&gt;Tracing route to vnsc-bak.sys.gtei.net [4.2.2.2]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp; 10.10.10.1&lt;BR /&gt;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Request timed out.&lt;/P&gt;&lt;P&gt;~&lt;/P&gt;&lt;P&gt; 29&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Request timed out.&lt;BR /&gt; 30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Request timed out.&lt;/P&gt;&lt;P&gt;Trace complete.&lt;/P&gt;&lt;P&gt;C:\&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Apr 2010 16:38:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353434#M856897</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-14T16:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353435#M856899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The .1.231 what kind of device is?&lt;/P&gt;&lt;P&gt;It could be that this device has no route back to the 10.10.10.0.24 network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Apr 2010 16:42:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353435#M856899</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-14T16:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353436#M856901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.231 is a Cisco 2811.&amp;nbsp; I put in a static route to the 10.10.10.0 network, still unable to ping from the 10.10.10.0/24 network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Apr 2010 16:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353436#M856901</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-14T16:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: 881G Router is unable to ping from the LAN side.  Any help?</title>
      <link>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353437#M856903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the 2811 (1.231) router I can ping inside the 10.10.10.0/24 network, just not the other way around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;perim2811#ping 10.10.10.2&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.10.10.2, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms&lt;BR /&gt;perim2811#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Apr 2010 16:56:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/881g-router-is-unable-to-ping-from-the-lan-side-any-help/m-p/1353437#M856903</guid>
      <dc:creator>Richard Baker</dc:creator>
      <dc:date>2010-04-14T16:56:03Z</dc:date>
    </item>
  </channel>
</rss>

