Link to home
Start Free TrialLog in
Avatar of kennycpu
kennycpu

asked on

How can I enable access the Cisco PIX outside NAT interface?

I setup one to one NAT from Cisco PIX, but I can't access or PING the ouside IP from internal network. Any Solution?
Avatar of Pete Long
Pete Long
Flag of United Kingdom of Great Britain and Northern Ireland image

outside ping is disabled by default

to turn it on toy need to add the following line to the config

icmp permit any echo outside

The ONLY way to manage a PIX from outside is via a VPN!! you need to enable a VPN to the firewall.
>I can't access or PING the ouside IP from internal network
Correct. This is by design of the pix.
What exactly are you trying to access with this ? Provide more information. Also mention if this nat you have created is resolved using external dns server.

Cheers,
Rajesh
Avatar of kennycpu
kennycpu

ASKER

Of course I can ping outside IP from outside. I mean I cannot access the ouside NAT IP from inside network.
I am now using 2 DNS server, One for outside REAL IP setting. Another use for internal DNS server which set with internal LAN IP.
ASKER CERTIFIED SOLUTION
Avatar of rsivanandan
rsivanandan
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Why shoot the messenger with a C grade (actually the 2nd messenger) just because you don't like the answer?

Don't expect anybody to answer your future questions if this is the way you judge them. First of all this has to be split and grade C just because it can't be done ? I don't own Cisco.