Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX Outside Interface Ping Reply?

I'm fairly new to PIX and recently configured a new 506e running 6.3(5). Something I noticed straight after bringing the outside interface up was that I could ping the outside IP address from the internet (from different ISP). Is it suppose to be this way? I thought a PIX would block this by default? If this is correct, how do I block replies from this interface?

1 ACCEPTED SOLUTION

Accepted Solutions
Hall of Fame Super Blue

Re: PIX Outside Interface Ping Reply?

Hi

If you want to block icmp to your outside pix interface from config mode on the pix

"no icmp permit any outside"

You can be more granular than this and allow certain addresses to ping your outside interface rather than deny all addresses as the above command does. I don't know whether you need this or not.

HTH

Jon

3 REPLIES
Hall of Fame Super Blue

Re: PIX Outside Interface Ping Reply?

Hi

If you want to block icmp to your outside pix interface from config mode on the pix

"no icmp permit any outside"

You can be more granular than this and allow certain addresses to ping your outside interface rather than deny all addresses as the above command does. I don't know whether you need this or not.

HTH

Jon

New Member

Re: PIX Outside Interface Ping Reply?

Hi Jon. Thanks! That certainly helped. The answer is slightly different though. It should be "icmp deny any outside". That's all I needed.

Johan

Hall of Fame Super Blue

Re: PIX Outside Interface Ping Reply?

Johan

Sorry about that, i slipped into IOS mode there :-)

Many thanks for the rating

Jon

194
Views
0
Helpful
3
Replies