Pix 525 Outside Interface is up but I cannot ping out..

Unanswered Question
May 1st, 2007
User Badges:

On 4/30/07 the two Pix 525 were working just fine. I have PPTP and IPSec VPN access configured. Today I find that the outside interface on both are up but that I cannot ping to the PBR connected to the outside interface. the only change made today was replacing the old outside IPs with new ones. I am not sure if the problem existed this morning before the IP address change. Is there a way to diagnose what is happening here?


Thanks

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Patrick Iseli Tue, 05/01/2007 - 16:45
User Badges:
  • Gold, 750 points or more

You need to permit ICMP in the outside access-list.


See: Handling ICMP Pings with the PIX Firewall

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml


The PIX and the traceroute Command

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800e9312.shtml


example:

access-list 101 permit icmp any host YourPublicIP unreachable

access-list 101 permit icmp any host YourPublicIP time-exceeded

access-list 101 permit icmp any host YourPublicIP echo-reply


Note replace the <101> with your ACL name.


sincerely

Patrick

Actions

This Discussion