cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
419
Views
0
Helpful
3
Replies

PIX Outside Interface Ping Reply?

jrossouw
Level 1
Level 1

I'm fairly new to PIX and recently configured a new 506e running 6.3(5). Something I noticed straight after bringing the outside interface up was that I could ping the outside IP address from the internet (from different ISP). Is it suppose to be this way? I thought a PIX would block this by default? If this is correct, how do I block replies from this interface?

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

Hi

If you want to block icmp to your outside pix interface from config mode on the pix

"no icmp permit any outside"

You can be more granular than this and allow certain addresses to ping your outside interface rather than deny all addresses as the above command does. I don't know whether you need this or not.

HTH

Jon

View solution in original post

3 Replies 3

Jon Marshall
Hall of Fame
Hall of Fame

Hi

If you want to block icmp to your outside pix interface from config mode on the pix

"no icmp permit any outside"

You can be more granular than this and allow certain addresses to ping your outside interface rather than deny all addresses as the above command does. I don't know whether you need this or not.

HTH

Jon

Hi Jon. Thanks! That certainly helped. The answer is slightly different though. It should be "icmp deny any outside". That's all I needed.

Johan

Johan

Sorry about that, i slipped into IOS mode there :-)

Many thanks for the rating

Jon

Review Cisco Networking products for a $25 gift card