PIX to 2811

Unanswered Question
Feb 24th, 2007

I have PIX 515 that I am trying to get to point out to the internet through a 2811.

I can get to the internet through the 2811 if I connect directly to the router, however through the PIX I'm running into some problems.

Router Details:

Internal IP:

X.X.3.252 secondary

External IP:



Internal IP:

External IP:


Now, I can ping the internal interface of the router from the external interface of the PIX, but I cannot get to the external interface of the router from anywhere in the PIX.

I'm pretty sure it has to be a routing issue on the PIX... but I could be very, very wrong. Any help would be greatly appreciated!

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Jon Marshall Sat, 02/24/2007 - 14:46


Could be a number of things. When you say "from anywhere in the pix" do you mean from DMZ's / internal networks ?.

If so things to check

1) Routing as you mentioned. Generally speaking you would want a default route on the pix pointing to the 2811.

2) Nat on the pix. Are you doing it or not.

3) access-lists on the pix. If you are pinging from inside the pix to the router you will need an access-list on the outside interface of your pix allowing the ping back in as icmp is not stateful.

Could you explain where you are trying to ping from and send a sanitised copy of the pix config.



mrblister Mon, 02/26/2007 - 09:48

I had no access-list on the pix to allow ICMP back in. Thanks for the heads up.

Now I have a seperate problem:

I cannot telnet into my routers internal interface from behind the firewall. Any thoughts on what might be causing this?

Jon Marshall Mon, 02/26/2007 - 10:59


Have you allowed telnet from the host you are trying to get to ? eg assuming you are connecting from on the pix in config mode

telnet inside



mrblister Mon, 02/26/2007 - 12:34

I have a default rule that allows all inside traffic out, this includes telnet. I can telnet into smtp servers, etc. outside the router.

I just cant telnet into the inside interface of my router.

That interface has two IP's:

a private address:

a public address: X.X.3.225 (secondary)

Now here's the strange thing, I cant telnet to the 192.168 address, nor can I ping it. However, I can ping the .3.225 secondary address. Strange, they are both on the same interface, shouldnt I be able to hit both of them?

Jon Marshall Mon, 02/26/2007 - 23:54


Sorry my mistake, i mis read and thought you were talking about telnet to the pix.

Right. Does your router have a route back to the host you are pinging from ?

Can you ping both router addresses on the internal interface from your pix.

What you could do is do a bit of debugging on the pix ie

debug packet outside dst

debug packet outside src

If you then telnet you should be able to see the packets going back and forth.

(Be careful with the debug. If there is a lot of traffic going through your pix best to do it in a quiet period).


mrblister Tue, 02/27/2007 - 07:40

First off, thanks for the help Jon, much appreciated.

Second off, I cannot ping the private 192 address, however I can ping the public X.X.3.225 address.

I'll give debugging a shot and see if I cant get some more info.

Thanks again.


This Discussion