12-07-2005 06:32 PM - edited 02-21-2020 12:34 AM
Hi,
Pls find the attached diagram.
the requirement is:
1. inside servers should ping pix inside,dmz,outside interface.
2.the server in pix dmz should be able to ping pix dmz,inside,outside interface and all servers inside.
3. from ISA i should be able to ping pix inside,dmz,outside interface and all servers inside.
Pls advice how to configure PIX using version 6.3(4) and 7.0
Regards,
Prashanth
12-07-2005 10:50 PM
just a quick comment.
by default, any host connected to a pix interface can ping that particular interface only. e.g. inside host can ping pix inside interface; or dmz host can ping pix dmz interface. as far as i know, there is no workaround.
12-07-2005 11:18 PM
Hi,
First of all, PIX doesnt allow ping across its interfaces (i.e. inside subnet cant ping the DMZ or the outside interfaces of the PIX). But in order to allow a subnet to ping the interface it's directly connected to, apply: "permit icmp any
In order for subnets connected to different interfaces to ping each other, you need to make sure that address tranlsation is configured properly. For example, in order for the DMZ subnet hosts to ping internal servers, you might need to apply: static (inside,dmz)
Please let me know how things go with you.
Best regards,
Haitham
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide