cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2182
Views
0
Helpful
5
Replies

PIX inside to Outside..... connectivity

mahavirsj
Level 1
Level 1

I would like to know how do I ping or reach from my LAN to the external interface of the PIX or to my valid IP range of addresses.

e.g If I need to expose a host on my internal network I would do a static mapping and then assign a conduit statement.but when I try to ping to the valid IP address assigned I am not able to do so.

I would like to mention that I am able to reach all other internet sites.

Is this a security feature of PIX FW or can we use a valid IP to ping from the LAN.

Can anybody help me in this regard.

Thanks.

5 Replies 5

millerv
Level 1
Level 1

see page 6 -62 of the config guide.

build an acl and permit icmp any any

_bbb_
Level 1
Level 1

Hello,

You cant ping your external static to your pix assigned IP-Adesses....we had this problem that we mapped a outside adress to a DMZ webserver...from external it was all reachable..but from internal only by the DMZ ip Adress of the webserver...

Solution: Install an internal DNS Server...or...try with "alias command" on PIX

permit icmp isnt very healthy at all ;) (disable it after you tested all)

BBB

Thanks it worked.I got that.

Regards

Mahavir

may be you need to define acl and gateway to the external addr.

jose.calvillo
Level 1
Level 1

You can not ping the external interface of a PIX unless you specificly allow that with a conduit statement.

If you put a STATIC NAT in to assign an internal host with a public IP address then that public IP will be unavailable from your internal network.

Something to do with the PIX not allowing packets originating from the inside to hit the outside & then back to the same interface which the packets originated.

Review Cisco Networking for a $25 gift card