configure pix with dsl 837

Posted on 2010-01-06
Last Modified: 2012-05-08
I need help configuring my pix firewall 501
How do I get pc with ip address get on the internet?

Thanks for your response.

   PIX501 ( int dhcp with 837)       |

pixfirewall# show run
: Saved
PIX Version 6.3(5)
interface ethernet0 auto
interface ethernet1 100full
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password 2KFQnbNIdI.2KYOU encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname pixfirewall
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
pager lines 24
mtu outside 1500
mtu inside 1500
ip address outside dhcp setroute
ip address inside
ip audit info action alarm
ip audit attack action alarm
pdm location inside
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0 0
rip outside passive version 1
rip inside passive version 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout sip-disconnect 0:02:00 sip-invite 0:03:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
http server enable
http inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
telnet timeout 5
ssh timeout 5
console timeout 0
username dexter password uN3MgqA1lJAVWEBl encrypted privilege 2
terminal width 80
: end
Question by:snoozeit
    LVL 33

    Accepted Solution

    The config looks good to me....  

    Check the following

    1) make sure the PC is getting translated...try to get oubound on the PC then do a "show xlate" on the PIX.   You should see an entry for your PC.  

    2) make sure the pix can get outbound.   From the PIX Command line, try pinging the public internet (i.e. ping   You should get a reply.  

    3) If the pix can ping and the pc is NATing, try pinging outbound to the same address from the PC.   "ping"  

    4) See if you have any ip connectivity or perhaps some other issue like a dns problem.  


    Author Comment

    Hi Mike,

    Thanks for your reply,

    I can ping form the pix cli to the router interface and also any public ip address.

    I used a public dns so I can now access the internet from the pc.

    I cannot ping from the pc to to anywhere( the router interface or any public ip address)  looks like the pix is blocking icmp packets.




    LVL 33

    Assisted Solution

    Ah, the PIX will need some commands to allow the ping to pass through properly.   You will need something like the following:

    access-list 101 permit icmp any any echo-reply
    access-list 101 permit icmp any any source-quench
    access-list 101 permit icmp any any unreachable
    access-list 101 permit icmp any any time-exceeded
    access-group 101 in interface outside

    That should alllow you to ping from the internal PC.  


    Author Comment

    Awesome that did it for now : )


    Featured Post

    IT, Stop Being Called Into Every Meeting

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    Join & Write a Comment

    Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
    Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
    Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

    729 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now