PIX allow ICMP requests
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-04-2002 01:20 PM - edited 02-20-2020 09:59 PM
I have two networks connected together via Frame-Relay. One network has a PIX on it. There is an Access-list bound to the inside interface, which is what the Frame-traffic gets routed to.
Why is it, that I can't ping some systems on the network with the PIX? I can ping some systems, and others I can't.
I have "permit ICMP any any" on my access-list, why am I still getting denied on some IP's?? Any ideas?
Aaron Paxson
- Labels:
-
Other Network Security Topics
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2002 10:32 PM
If you already have icmp any any, do a logging buffered debugging on the pix and do a show log after you ping to see if the pix is denying it or some other acl on the next hop router. It would be a good practice to do a clear log before you do the test.
Make sure you are also trying to reach hosts that have translation, even specifying in the pix the same address or no translation for the inside hosts.
