03-22-2010 11:31 PM - edited 03-11-2019 10:24 AM
hi experts,
is it possible to ping the inside interface of the pix firewall from dmz or outside.. if yes, what are the configurations to be done on it..
pls help....
rajesh
Solved! Go to Solution.
03-23-2010 04:44 AM
No, you can only ping from directly connected interface, ie: from outside, you can only ping the outside interface, from dmz, you can only ping the dmz interface, etc etc.
If you are connecting via VPN on the outside interface, you can configure "management-access inside" to be able to ping the inside interface.
However you can only configure 1 management-access line, not multiple lines. Therefore you would need to choose which interface you would like to ping when you VPN in.
Here is the command for your reference:
http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/m.html#wp1987122
Hope that helps.
03-23-2010 02:43 AM
Hi,
This link will help
It states the following:
Pings initiated from the outside, or another low security interface of the PIX, are denied be default. The pings can be allowed by the use of static and access lists or access lists alone.
03-23-2010 03:42 AM
Hi,
thanks for your reply...
my intention is to ping to the INSIDE INTERFACE from any other dmzz/outside network !!!!
pls check and let me know...
rajesh
03-23-2010 03:52 AM
Can you please attach the running configuration file?
03-23-2010 04:35 AM
ethernet 0 outside -> 172.16.1.1
ethernet 2 dmz -> 192.168.1.1
ethernet 1 inside -> 10.0.0.1
icmp permit any inside
icmp permit any outside
icmp permit any dmz
access-list 101 permit ip any any
access-group 101 in interface inside
access-group 101 in interface outside
access-group 101 in interface dmz
03-23-2010 04:42 AM
I dont know the security level of the interfaces. So set the security-level to 100 for inside and dmz interface.
security-level 100
same-security-traffic permit intra-interface
access-group 101 out interface dmz
03-23-2010 04:44 AM
No, you can only ping from directly connected interface, ie: from outside, you can only ping the outside interface, from dmz, you can only ping the dmz interface, etc etc.
If you are connecting via VPN on the outside interface, you can configure "management-access inside" to be able to ping the inside interface.
However you can only configure 1 management-access line, not multiple lines. Therefore you would need to choose which interface you would like to ping when you VPN in.
Here is the command for your reference:
http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/m.html#wp1987122
Hope that helps.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: