Link to home
Start Free TrialLog in
Avatar of Ciderspine
Ciderspine

asked on

PIX internal to external icmp

Hi experts,

An easy one here:

I get no respose from my PIX's external interface when I ping it from the internal network - I can however ping the internet from the internal network . Is this normal behaviour of PIX - is it a limitation of NAT or is something up with my PIX?

Ciderspine
Avatar of uter
uter

It's probably blocking the ICMP protocol used by PING and TRACERT. If you enable that in the PIX, you should be able to ping it.
D'OH! I just noticed you said you can ping the internet... :)

I checked and it looks like it's a limitation of NAT - the external interface can't respond to a request from it's own internal interface.
Avatar of Ciderspine

ASKER

Thanks uter,

Yes, I do have ICMP rules. I just want to be sure that it's normal and not something in the way I've configured PIX. Where did you get the info from?

I can ping both interfaces from the PIX (ie - in a telnet session.)


Ciderspine
ASKER CERTIFIED SOLUTION
Avatar of uter
uter

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial