Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Cannot ping external sites in PIX

I cannot ping like "ping www.google.com" from PIX version 7.1

Please help...........

4 REPLIES
Cisco Employee

Re: Cannot ping external sites in PIX

Hi Debabrata,

Are you able to ping the isp i.e the next hop in the default route ? Also can you try to ping with the ip address of google.com not with the name.

Community Member

Re: Cannot ping external sites in PIX

Yes I am able to ping ip addresses from the PIX it's only the hostname that is not pinging it gives this error..

Ping www.google.com

        ^

invalid input after the marker.

Cisco Employee

Re: Cannot ping external sites in PIX

So if i m not wrong you have your dns server outside. I can see an acces-list applied on the outside permitting only icmp. Permit the dns replies and see you are able to ping. Add the following access-list :

access-list outside_in extended permit ip host

Cisco Employee

Re: Cannot ping external sites in PIX

Hi Debabrata,

Support for pinging with DNS names instead of IP addresses wasn't added until 7.2(1), per the command reference:

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/p.html#wp1882586

If pinging with DNS names from the PIX is a requirement for you, you'll need to upgrade to 7.2(1) or higher.

Hope that helps.

-Mike

385
Views
5
Helpful
4
Replies
CreatePlease to create content