Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

pix515 no resolution from inside

I configured a pix 515. users in the lan can ping machine on the internet but cannot load any internet pages. pc on the lan have the right dns server.

please how can i resolv the dns problem ?

1 ACCEPTED SOLUTION

Accepted Solutions
Green

Re: pix515 no resolution from inside

no access-list ping_acl permit icmp any any

no access-group ping_acl in interface inside

You do not need this acl to allow ping from the inside interface. Removing this acl will solve your dns problems etc. If you want to ping to the outside you only need to allow the reply in the outside interface acl like so...

access-list acl_out permit icmp any any echo-reply

Please rate if this helps.

7 REPLIES
Green

Re: pix515 no resolution from inside

Is there an acl on the inside interface?

Community Member

Re: pix515 no resolution from inside

hi,

Yes, just one to permit ping :

access-list ping_acl permit icmp any any

access-group ping_acl in interface inside

Find attached the configuration file.

Regards

Community Member

Re: pix515 no resolution from inside

Hello.

The ping_acl is your problem.

You will need to add a line allowing users port 80 connections out (there maybe other ports required also)

Tim

Community Member

Re: pix515 no resolution from inside

ok,

addind a line like with an acl? how ?

access-list out_acl permit tcp inside-network any eq 80

is it correct ?

Regards

Community Member

Re: pix515 no resolution from inside

Is it possible to see a configuration?

Community Member

Re: pix515 no resolution from inside

Yes, please find attached the configuration file.

Regards

Green

Re: pix515 no resolution from inside

no access-list ping_acl permit icmp any any

no access-group ping_acl in interface inside

You do not need this acl to allow ping from the inside interface. Removing this acl will solve your dns problems etc. If you want to ping to the outside you only need to allow the reply in the outside interface acl like so...

access-list acl_out permit icmp any any echo-reply

Please rate if this helps.

141
Views
5
Helpful
7
Replies
CreatePlease to create content