cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1388
Views
0
Helpful
2
Replies

Block ICMP at PIX outside interface

tkpsimon
Level 1
Level 1

Hi just wonder how can i stop icmp from outside at my PIX outside interface, i try to put acl on my access-group outside, but i can still ping from outside, am i missing something?

access-list acl_out deny icmp any any

access-group acl_out in interface outside

2 Replies 2

gfullage
Cisco Employee
Cisco Employee

I presume you're trying to stop pings TO the PIX's outside interface, is that right?

Remember that ACL's only apply to traffic travelling THROUGH the PIX, not TO it specifically. If you want to stop the PIX from answering pings you need to use the "icmp" command.

See http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/gl.htm#1026574 for details.

minoc
Level 1
Level 1

You need to use the icmp command under privilige mode:

conf t

icmp deny any outside

Regards,

Carlos Roque