But when I try to connect to internet the PIX do not NAT the client IP address. But when I do a ping the PIX will NAT the client interface but still cannot touch the target host (I have create and apply an access list to permit ICMP). The software version is 6.2 (2). Is it bug?
Have try to clear the transation. But still won't works. The PIX have 3 interface. It is ok right. I can ping from the PIX to the DNS. But not from the client side. The PIX will translate for the ICMP but with no return. When using the http the PIX not translate them.
You should not use ICMP to test for translations, cause ICMP is not handled by the ASA. All other traffic is, so, testing with tcp or udp will work with your current setup. If you especially want to test with ICMP you have to set some rules oin your outside in access-list to let the ICMP response traffic in :-)
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
[toc:faq]Introduction:This document describes details on how NAT-T
works.Background:ESP encrypts all critical information, encapsulating
the entire inner TCP/UDP datagram within an ESP header. ESP is an IP
protocol in the same sense that TCP and UDP are I...