cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
674
Views
0
Helpful
1
Replies

Can't stop icmp on PIX

stoneystone
Level 1
Level 1

I have a problem with a PIX 501 Ver 6.3(3) and stopping icmp. I have added the following commands, but I can still ping my firewall's outside interface. Any ideas?

firewall# sh access-list

access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 256)

alert-interval 300

access-list acl-in; 15 elements

access-list acl-in line 1 deny icmp any any (hitcnt=39227)

access-list acl-in line 2 deny icmp any any echo-reply (hitcnt=0)

access-list acl-in line 3 deny icmp any any unreachable (hitcnt=0)

access-list acl-in line 4 deny icmp any any time-exceeded (hitcnt=0)

access-list acl-in line 5 deny icmp any any source-quench (hitcnt=0)

access-list acl-in line 6 deny udp any any eq tftp (hitcnt=0)

access-list acl-in line 7 deny udp any any eq 135 (hitcnt=0)

access-list acl-in line 8 deny tcp any any eq 135 (hitcnt=0)

access-list acl-in line 9 deny tcp any any eq netbios-ssn (hitcnt=0)

access-list acl-in line 10 deny udp any any eq netbios-ns (hitcnt=0)

access-list acl-in line 11 deny udp any any eq netbios-dgm (hitcnt=0)

access-list acl-in line 12 deny tcp any any eq 445 (hitcnt=0)

access-list acl-in line 13 deny tcp any any eq 593 (hitcnt=0)

access-list acl-in line 14 permit udp any any eq 22 (hitcnt=0)

access-list acl-in line 15 deny ip any any (hitcnt=11652)

firewall# sh access-group

access-group acl-in in interface outside

firewall#

Thanks

1 Reply 1

jgayou
Level 1
Level 1

Ping to the PIX is stopped not by an access-list but with the icmp command

To stop ping to the outside of the PIX

icmp deny any outside

Thanks

Jeremy Gayou

CCIE #12341