PIX Outside Interface Ping Reply?

Answered Question
Mar 18th, 2007
User Badges:

I'm fairly new to PIX and recently configured a new 506e running 6.3(5). Something I noticed straight after bringing the outside interface up was that I could ping the outside IP address from the internet (from different ISP). Is it suppose to be this way? I thought a PIX would block this by default? If this is correct, how do I block replies from this interface?

Correct Answer by Jon Marshall about 10 years 1 month ago

Hi


If you want to block icmp to your outside pix interface from config mode on the pix


"no icmp permit any outside"


You can be more granular than this and allow certain addresses to ping your outside interface rather than deny all addresses as the above command does. I don't know whether you need this or not.


HTH


Jon


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Jon Marshall Sun, 03/18/2007 - 08:33
User Badges:
  • Super Blue, 32500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

Hi


If you want to block icmp to your outside pix interface from config mode on the pix


"no icmp permit any outside"


You can be more granular than this and allow certain addresses to ping your outside interface rather than deny all addresses as the above command does. I don't know whether you need this or not.


HTH


Jon


jrossouw Sun, 03/18/2007 - 08:44
User Badges:

Hi Jon. Thanks! That certainly helped. The answer is slightly different though. It should be "icmp deny any outside". That's all I needed.


Johan

Jon Marshall Sun, 03/18/2007 - 10:09
User Badges:
  • Super Blue, 32500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

Johan


Sorry about that, i slipped into IOS mode there :-)


Many thanks for the rating


Jon

Actions

This Discussion