cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
367
Views
0
Helpful
1
Replies

How pix handels ICMP using PAT--

hjerbandi
Level 1
Level 1

@All,

Would like to know how pixs handles ICMP pkts(eg ping) while uisng PAT. How will it differentiate between 2 ping request commings from the internal network to the same destination??

any referedce doc/url will be appericated!!!

thx

hanu

1 Reply 1

nkhawaja
Cisco Employee
Cisco Employee

Hi,

I believe it does try to implement virtual ports for icmp packets as well just like we have ports in tcp and udp and pix maintains this information in port table.

Here is syslog message from two different source ports trying to send icmp to a destiantion port

%FWSM-6-305011: Built dynamic icmp translation from inside:17x.6x.227.146/14832 to outside:172.16.171.201/1025

%FWSM-6-305011: Built dynamic icmp translation from inside:17x.6x.8x.158/21692 to outside:172.16.171.201/1026

you can see it is implemeing ports for icmp sessions as well.

Thanks

Nadeem

Review Cisco Networking for a $25 gift card