?
Solved

PIX internal to external icmp

Posted on 2006-03-29
4
Medium Priority
?
308 Views
Last Modified: 2013-11-29
Hi experts,

An easy one here:

I get no respose from my PIX's external interface when I ping it from the internal network - I can however ping the internet from the internal network . Is this normal behaviour of PIX - is it a limitation of NAT or is something up with my PIX?

Ciderspine
0
Comment
Question by:Ciderspine
  • 3
4 Comments
 
LVL 1

Expert Comment

by:uter
ID: 16326775
It's probably blocking the ICMP protocol used by PING and TRACERT. If you enable that in the PIX, you should be able to ping it.
0
 
LVL 1

Expert Comment

by:uter
ID: 16326809
D'OH! I just noticed you said you can ping the internet... :)

I checked and it looks like it's a limitation of NAT - the external interface can't respond to a request from it's own internal interface.
0
 

Author Comment

by:Ciderspine
ID: 16327331
Thanks uter,

Yes, I do have ICMP rules. I just want to be sure that it's normal and not something in the way I've configured PIX. Where did you get the info from?

I can ping both interfaces from the PIX (ie - in a telnet session.)


Ciderspine
0
 
LVL 1

Accepted Solution

by:
uter earned 750 total points
ID: 16333022
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question