ANNOUNCEMENT - The community will be down for maintenace this Thursday August 13 from 12:00 AM PT to 02:00 AM PT. As a precaution save your work.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
149
Views
0
Helpful
2
Replies
Highlighted
Beginner

PATed ip responds icmp from outside

hi guys, so i ran into this thing with pat on a cisco router. 
i always thought that pat only allowed traffic inside to outside, but i found a scenario that when a pat translation
is generated by legitimate traffic, then the pated ip address starts responding ping from outside. 
the cisco router is the host responding to the icmp.

The PATed ip address is not assigned to the interface.
is this behavior normal? couldn't find any information on cisco regarding this.


see diagram and config attached

2 REPLIES 2
Highlighted
Engager

hi,i don't think is due to

hi,

i don't think is due to PAT/NAT that ping is working.

maybe it's just due to normal routing that the router does.

could you post configs, pings and debug ip nat detailed output?

Highlighted
Beginner

hi, please see attached file

hi, please see attached file screenshot_2.jpg, its a reproduction of the config in gns3. 

The pc is nated to 192.168.1.2 which is a PAT, when that entry is crated in the nat table, that ip address starts responding to ping from outside, the router is the device responding to ping as seen in a capture in gns3.