?
Solved

How can I enable access the Cisco PIX outside NAT interface?

Posted on 2006-11-02
8
Medium Priority
?
208 Views
Last Modified: 2013-11-16
I setup one to one NAT from Cisco PIX, but I can't access or PING the ouside IP from internal network. Any Solution?
0
Comment
Question by:kennycpu
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 17856823
outside ping is disabled by default

to turn it on toy need to add the following line to the config

icmp permit any echo outside

The ONLY way to manage a PIX from outside is via a VPN!! you need to enable a VPN to the firewall.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 17857222
>I can't access or PING the ouside IP from internal network
Correct. This is by design of the pix.
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17868461
What exactly are you trying to access with this ? Provide more information. Also mention if this nat you have created is resolved using external dns server.

Cheers,
Rajesh
0
Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

 

Author Comment

by:kennycpu
ID: 17882654
Of course I can ping outside IP from outside. I mean I cannot access the ouside NAT IP from inside network.
0
 

Author Comment

by:kennycpu
ID: 17882674
I am now using 2 DNS server, One for outside REAL IP setting. Another use for internal DNS server which set with internal LAN IP.
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 200 total points
ID: 17882701
If you have the dns server internally for this REAL ip, then there is nothing that can be done. It is per design as Lrmoore stated.

Cheers,
Rajesh
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 17914989
Why shoot the messenger with a C grade (actually the 2nd messenger) just because you don't like the answer?

0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17915049
Don't expect anybody to answer your future questions if this is the way you judge them. First of all this has to be split and grade C just because it can't be done ? I don't own Cisco.

0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question