Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

501 to internal host.

I am a total cisco newbie, so please don't make fun if me if I am doing something totally stupid.

I am haveing some problems setting up my pix 501 to allow access to an internal host. I originally tried the web based setup for the 501, but it didn't work. So I am trying the command line to set it up. So, here goes.

I am trying to allow access to an internal web server (and allow icmp packets, ping, to reach it). Here is one of many things i have tried.

(*all IP's are used as examples only)

Internal IP of HOST -

Internal IP of PIX -

External IP of PIX -

O.K.. So I set up the internal and external interfaces (by default, the 501 names them inside and outside, go figure).

I then ping the external ip from and external machine and the internal ip (of the pix) from an internal ip. They both work fine. Time to move on.

I then set up a static nat.

static (inside,outside) netmask 0 0

When I do this, I can no longer ping the outside IP address of the pix. Thats how it's supposed to be (I assume). I have to set up permissions.. Since the 501 doesn't support access-list. I have to use conduit.

conduit permit icmp host eq icmp all

I have tried various commands on the conduit command includeing

conduit permit tcp host eq http any (etc, etc, etc).. Each time trying the approprait thing I had tried to set up (web, mail, telnet, ftp, etc. etc.)..

I have NO idea what I am doing wrong here. Nothing seems to work. As soon as I start setting up the static nat, nothing seems to work any longer..



Re: 501 to internal host.

Take a look at this Technical Tips page. There are sample configurations for NAT and conduits. There are other links on there as well that will help you in the future.

New Member

Re: 501 to internal host.

Yes, I did.. Have it set up exactly as discribed in this link (with the correct IP's, of course). Still doesn't work though.

Re: 501 to internal host.

"Since the 501 doesn't support access-list. I have to use conduit"?????

The PIX 501 does support access-lists!!!!!!!

Please have a look at this URL for more info (skip the conduit commands):

Kind Regards,


CreatePlease login to create content