08-30-2007 03:12 AM - edited 03-11-2019 04:04 AM
Hi All,
I have a server farm on my DMZ. I have statically NATted the Servers' IP addresses to other IP addresses for the inside & outside networks. I can http in to web server's NATted IP, but i cannot ping these addresses. Is there a way i can ping these virtual addresses.
Can i use the subinterfaces on say the outside or inside interfaces to assign public IPs and then map the addresses of the servers on DMZ to those on the subinterfaces.
08-30-2007 05:40 AM
Yes you can do but in that case your all OUTSIDE INterface has priority will be 0.
Open Access list ICMP extended to ping.
Regards,
Dharmesh
08-30-2007 09:00 AM
To allow inbound pings, you must specify on your outside acl:
permit icmp any any echo
To allow outbound pings (the return response), again, on your outside acl:
permit icmp any any echo-reply
These assume you have no outbound acl's.
The other option, turn on icmp inspection.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide