<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX or router issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185209#M876608</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from the pix can you ping the internet router?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Feb 2009 11:43:51 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2009-02-11T11:43:51Z</dc:date>
    <item>
      <title>PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185208#M876607</link>
      <description>&lt;P&gt;Following is a lab topology:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot ping from interent(LAB) router to the inside interface of pix as well as lan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ALso cannot ping outside interface of Pix from lan but can ping the system on internet(LAB) .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;system A ------&amp;gt;switch-------&amp;gt;LAN Router----&amp;gt;firewall---&amp;gt;Internet Router-----&amp;gt;Switch-----&amp;gt;System B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System A IP:10.1.2.5/24&lt;/P&gt;&lt;P&gt;gateway:    10.1.2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System B ip:172.16.10.5/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------&lt;/P&gt;&lt;P&gt;LAN Router Configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; ip address 10.1.2.1 255.255.255.0&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; ip address 10.1.1.2 255.255.255.0&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.1.1.1&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.165.200.226 255.255.255.224&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any echo&lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list 100 extended permit tcp any any eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 10.165.200.227-10.165.200.254 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.165.200.228 10.1.2.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group 100 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 10.165.200.225 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.1.2.0 255.255.255.0 10.1.1.2 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------------------&lt;/P&gt;&lt;P&gt;Internet Router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; ip address 10.165.200.225 255.255.255.224&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; ip address 172.16.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:48:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185208#M876607</guid>
      <dc:creator>seekhpar121</dc:creator>
      <dc:date>2019-03-11T14:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185209#M876608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from the pix can you ping the internet router?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2009 11:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185209#M876608</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-11T11:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185210#M876609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FRom system A:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)CAN ping System B.&lt;/P&gt;&lt;P&gt;2)CANNOT ping outside interface of pix&lt;/P&gt;&lt;P&gt;3)CAN ping ETH0 of internet router connected to outisde interface of pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can ping Internet router as well as System B:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From Internet Router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cannot ping Inisde interface of PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From System B:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When ping inside interface of pix:Result is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reply from 172.16.10.1:destination host unreachable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Waiting for more replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 04:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185210#M876609</guid>
      <dc:creator>seekhpar121</dc:creator>
      <dc:date>2009-02-12T04:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185211#M876610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is normal behaviour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the outside of the pix you will not be able to ping the inside IP.  From the inside of the pix you will not be able to ping the outside IP = all normal for the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your network connectivity tests that prove the network from end to end will be:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;system A ping switch = OK&lt;/P&gt;&lt;P&gt;system A ping LAN Router = OK&lt;/P&gt;&lt;P&gt;system A ping firewall inside = OK&lt;/P&gt;&lt;P&gt;system A ping internet router = OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above proves the system A side 100%&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;system B ping switch = OK&lt;/P&gt;&lt;P&gt;system B ping internet router = OK&lt;/P&gt;&lt;P&gt;system B ping firewall outside = OK&lt;/P&gt;&lt;P&gt;system B ping LAN router = OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above proves the system B side 100%&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;system B ping system A = OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That means you have 100% end to end connectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 10:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185211#M876610</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-12T10:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185212#M876611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; system B cannot ping LAN Router,&lt;/P&gt;&lt;P&gt;Response is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reply from 172.16.10.1(internet Router ip),destination host unreachable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also System B cannot ping System A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX os is v8.0(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 04:09:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185212#M876611</guid>
      <dc:creator>seekhpar121</dc:creator>
      <dc:date>2009-02-13T04:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185213#M876612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then the issue has nothing to do with the firewall - it is a mi-configuration on the internet router.  Post for review.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 08:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185213#M876612</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-13T08:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185214#M876613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following is the internet router configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet Router: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0 &lt;/P&gt;&lt;P&gt;ip address 10.165.200.225 255.255.255.224 &lt;/P&gt;&lt;P&gt;half-duplex &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface FastEthernet0 &lt;/P&gt;&lt;P&gt;ip address 172.16.10.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;speed auto &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 14:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185214#M876613</guid>
      <dc:creator>seekhpar121</dc:creator>
      <dc:date>2009-02-13T14:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185215#M876614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - are you allowing icmp requests thru the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 14:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185215#M876614</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-13T14:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185216#M876615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AT PIX for allowing icmp as well as routes and static natting of system A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any echo &lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group 100 in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.165.200.228 10.1.2.5 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 10.165.200.225 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.1.2.0 255.255.255.0 10.1.1.2 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Feb 2009 03:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185216#M876615</guid>
      <dc:creator>seekhpar121</dc:creator>
      <dc:date>2009-02-14T03:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: PIX or router issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185217#M876616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to re think your config - on what you want to allow thru the firewall and how you NAT that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post a network diagram of your test network including your IP subnets.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Feb 2009 08:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-or-router-issue/m-p/1185217#M876616</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-14T08:37:38Z</dc:date>
    </item>
  </channel>
</rss>

