permit the following on the inbound acl:
access-list 101 permit icmp any any unreachable
access-list 101 permit icmp any any time-exceeded
access-list 101 permit icmp any any echo-reply
http://www.cisco.com/warp/public/110/pixtrace.html
optionally, enable icmp inspection