cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
346
Views
0
Helpful
2
Replies

PATed ip responds icmp from outside

Ignacio Freyre
Level 1
Level 1

hi guys, so i ran into this thing with pat on a cisco router. 
i always thought that pat only allowed traffic inside to outside, but i found a scenario that when a pat translation
is generated by legitimate traffic, then the pated ip address starts responding ping from outside. 
the cisco router is the host responding to the icmp.

The PATed ip address is not assigned to the interface.
is this behavior normal? couldn't find any information on cisco regarding this.


see diagram and config attached

2 Replies 2

johnlloyd_13
Level 9
Level 9

hi,

i don't think is due to PAT/NAT that ping is working.

maybe it's just due to normal routing that the router does.

could you post configs, pings and debug ip nat detailed output?

hi, please see attached file screenshot_2.jpg, its a reproduction of the config in gns3. 

The pc is nated to 192.168.1.2 which is a PAT, when that entry is crated in the nat table, that ip address starts responding to ping from outside, the router is the device responding to ping as seen in a capture in gns3.

Review Cisco Networking for a $25 gift card