Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ICMP not working with NAT ??

I set PAT for going internet through public IPa,

"Internal-IPs" -->"Public-IPa" --->"internet"

I also have a static NAT mapping "public-Ipa" to a "internal-IPa" for some reason,

"Internal-IPa" <--> "Public-IPa"

they all set at the same firwall. everything looks fine, the only problem is i cannot ping from internal to internet, all other traffic can pass, www, telnet ,ssh ,.....

I trace the ICMP traffic and found the echo reply actually come back to my firewall but they forward to the "Internal-IPa" istead of the real internal host? I pretty sure it is the static NAT? But other traffic like http, when the packets come back to the firewall, the firewall can forward them to the right internal host rather than the static-nat host???

I am so confuse, is there any different between NATing ICMP traffic and other traffic ????


Re: ICMP not working with NAT ??

Check whether you configure the command "fixup protocol icmp error" or not.

New Member

Re: ICMP not working with NAT ??

I do not have this command in the firewall. I removed the static NAT and it works fine. But i still do not understand why normal traffic works with the static NAT but only ICMP not !!!