<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 501 ping issue and irregularity in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851193#M957974</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the incredibly quick reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately those commands gave me an error - "Type help or '?' for a list of available commands.".  I'm guessing they're Pix 7.x commands, and I can't upgrade to 7.  I'm on 6.3(5).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Dec 2007 21:55:09 GMT</pubDate>
    <dc:creator>miket</dc:creator>
    <dc:date>2007-12-27T21:55:09Z</dc:date>
    <item>
      <title>Pix 501 ping issue and irregularity</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851190#M957971</link>
      <description>&lt;P&gt;I'm new to Cisco and I have a Pix 501 running 6.3(5).  I found I was unable to ping.  So I did some research and found the document "Handling ICMP Pings and traceroute...", applied the access-list as recommended but it didn't appear to work.  Then I found 'icmp permit any echo inside' and I thought it worked - I was able to ping.&lt;/P&gt;&lt;P&gt;Now after playing with it a little more - trying to get the access-list... part working, I cannot get echos at all.  If anyone can offer some assistance, I could use some help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike Trout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the (hopefully) relevant parts of my config (full config attached). (10.254.254.132 is my workstation - I also want to be able to ping from anywhere in the 10.254.254.x subnet (inside) to outside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl permit ip any 10.254.254.240 255.255.255.240&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl permit ip 10.254.254.0 255.255.255.0 10.254.254.240 255.255.255.240&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl permit ip any 10.254.254.248 255.255.255.248&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_40 permit ip any 10.254.254.240 255.255.255.240&lt;/P&gt;&lt;P&gt;access-list NeumaTest1_splitTunnelAcl permit ip 10.254.254.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_60 permit ip any 10.254.254.240 255.255.255.240&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_80 permit ip any 10.254.254.248 255.255.255.248&lt;/P&gt;&lt;P&gt;access-list NeumaRemote_splitTunnelAcl permit ip 10.254.254.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list Emergency_splitTunnelAcl permit ip 10.254.254.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any host 10.254.254.132 echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any host 10.254.254.132 source-quench&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any host 10.254.254.132 unreachable&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any host 10.254.254.132 time-exceeded&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;icmp permit any echo inside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside pppoe setroute&lt;/P&gt;&lt;P&gt;ip address inside 10.254.254.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool Remote 10.254.254.241-10.254.254.250&lt;/P&gt;&lt;P&gt;ip local pool emergency 10.254.254.251-10.254.254.252&lt;/P&gt;&lt;P&gt;ip local pool Testing 10.254.254.253-10.254.254.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851190#M957971</guid>
      <dc:creator>miket</dc:creator>
      <dc:date>2019-03-13T00:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 ping issue and irregularity</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851191#M957972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike&lt;/P&gt;&lt;P&gt;Try this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy &lt;/P&gt;&lt;P&gt;class inspection_default &lt;/P&gt;&lt;P&gt;inspect icmp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 21:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851191#M957972</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-27T21:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 ping issue and irregularity</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851192#M957973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oops - forgot to sanitize my config... Sanitized config here...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 21:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851192#M957973</guid>
      <dc:creator>miket</dc:creator>
      <dc:date>2007-12-27T21:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 ping issue and irregularity</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851193#M957974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the incredibly quick reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately those commands gave me an error - "Type help or '?' for a list of available commands.".  I'm guessing they're Pix 7.x commands, and I can't upgrade to 7.  I'm on 6.3(5).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 21:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851193#M957974</guid>
      <dc:creator>miket</dc:creator>
      <dc:date>2007-12-27T21:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 ping issue and irregularity</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851194#M957975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,  to allow any inside host to ping any host on the outside you have to do it the way the link explained it and apply the acl 101 to outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any source-quench &lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any unreachable  &lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in fact you only need two lines , but try it either way but don't forget to apply acl 101 to outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 22:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851194#M957975</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-27T22:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 ping issue and irregularity</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851195#M957976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for replying.  The 'any any' construction was listed for the 7.x version only, so I didn't try it.  I tried to duplicate the construction for the 6.3 version and was unable to make it work.  Also, I did have the access-group... command in the config, but (apparently) clipped it from the post.  Of course, if the acl wasn't constructed right, it didn't matter...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyways, it appears to work now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, one more question - when I tracert somewhere (google.com, cisco.com, wherever...) from my workstation, the Pix is completely blank.  When I tracert from my cheap linksys router at home, the internal lines are there - something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tracert google.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tracing route to google.com [xx.x.x.x]&lt;/P&gt;&lt;P&gt;over a maximum of 30 hops:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 1   8ms   8ms   7ms   xxxx.xxxx.sbcglobal.net [x.x.x.x]&lt;/P&gt;&lt;P&gt; 2   8ms   8ms   7ms  xxx.xxxx.xxxx.sbcglobal.net [x.x.x.x]&lt;/P&gt;&lt;P&gt; 3... (etc.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but at home I get the first 1 or 2 being the inside interface, and (not there to test) maybe an outside interface as well - so the first line is always:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1  X ms  X ms   Xms   10.x.x.1 (the default gateway address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that normal?  Is there a reason it does that? (the pix that is).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 23:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851195#M957976</guid>
      <dc:creator>miket</dc:creator>
      <dc:date>2007-12-27T23:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 501 ping issue and irregularity</title>
      <link>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851196#M957977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is normal behaviour in pix 6.x, when doing traceroute the pix interface ip address will not show up in the traceroute and it will appear as one hop is missing in the traceroute output. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See this link for backround on icmp and traceroute commands on 6.x and 7.x and its association of these commands with NAT and PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 00:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-501-ping-issue-and-irregularity/m-p/851196#M957977</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-28T00:10:01Z</dc:date>
    </item>
  </channel>
</rss>

