12-03-2003 01:25 PM
Hi just wonder how can i stop icmp from outside at my PIX outside interface, i try to put acl on my access-group outside, but i can still ping from outside, am i missing something?
access-list acl_out deny icmp any any
access-group acl_out in interface outside
12-03-2003 05:09 PM
I presume you're trying to stop pings TO the PIX's outside interface, is that right?
Remember that ACL's only apply to traffic travelling THROUGH the PIX, not TO it specifically. If you want to stop the PIX from answering pings you need to use the "icmp" command.
See http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/gl.htm#1026574 for details.
12-16-2003 11:41 AM
You need to use the icmp command under privilige mode:
conf t
icmp deny any outside
Regards,
Carlos Roque
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide