09-04-2003 11:16 AM - edited 02-20-2020 10:58 PM
Hi
I want to prevent my external PIX interface from being "pinged". I removed the "conduit permit icmp any any" statement and added a "conduit deny icmp any any" command. Now I cannot ping anything on the Internet nor can anyone ping any of my NATed addesses but I can still ping my external PIX interface. What am I missing? Thanks
09-04-2003 11:50 AM
Hi,
Conduits and Access-list only affect (effect, I can never remember) transit traffic. That is, traffic that is going *through* the PIX rather than *to* the PIX. I believe you are more interested in the 'icmp deny' command - http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/gl.htm#1026574
Scott
09-04-2003 12:13 PM
Beautiful, thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide