<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to allow ICMP when doing TCP PAT? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-allow-icmp-when-doing-tcp-pat/m-p/827513#M969744</link>
    <description>&lt;P&gt;PIX-515E running 7.2.2&lt;/P&gt;&lt;P&gt;Internal network on private IP addresses, external network on public addresses.&lt;/P&gt;&lt;P&gt;Each internal Web server has its own external IP address. PIX is doing PAT, mapping the external port 80/tcp to port 8080/tcp internally on each Web server like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp web1-ext 80 web1-int 8080 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is, now I cannot allow ICMP echo requests to the Web servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I did NAT (see below) then ICMP would be able to pass, but I need to translate the port too, so this won't work for me:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) web1-ext web1-int netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to do PAT (80--&amp;gt;8080) but also allow inbound ICMP echo requests?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:08:57 GMT</pubDate>
    <dc:creator>hws_admin</dc:creator>
    <dc:date>2019-03-11T11:08:57Z</dc:date>
    <item>
      <title>How to allow ICMP when doing TCP PAT?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-icmp-when-doing-tcp-pat/m-p/827513#M969744</link>
      <description>&lt;P&gt;PIX-515E running 7.2.2&lt;/P&gt;&lt;P&gt;Internal network on private IP addresses, external network on public addresses.&lt;/P&gt;&lt;P&gt;Each internal Web server has its own external IP address. PIX is doing PAT, mapping the external port 80/tcp to port 8080/tcp internally on each Web server like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp web1-ext 80 web1-int 8080 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is, now I cannot allow ICMP echo requests to the Web servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I did NAT (see below) then ICMP would be able to pass, but I need to translate the port too, so this won't work for me:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) web1-ext web1-int netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to do PAT (80--&amp;gt;8080) but also allow inbound ICMP echo requests?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:08:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-icmp-when-doing-tcp-pat/m-p/827513#M969744</guid>
      <dc:creator>hws_admin</dc:creator>
      <dc:date>2019-03-11T11:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow ICMP when doing TCP PAT?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-icmp-when-doing-tcp-pat/m-p/827514#M969749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I don't think that's possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2007 16:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-icmp-when-doing-tcp-pat/m-p/827514#M969749</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-09-10T16:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow ICMP when doing TCP PAT?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-icmp-when-doing-tcp-pat/m-p/827515#M969753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's not possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2007 17:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-icmp-when-doing-tcp-pat/m-p/827515#M969753</guid>
      <dc:creator>hsajwan</dc:creator>
      <dc:date>2007-09-10T17:48:41Z</dc:date>
    </item>
  </channel>
</rss>

