cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
388
Views
0
Helpful
5
Replies

PIX OS Upgrade problems (unable to ping)

tvorhauer
Level 1
Level 1

My problems have been snowballing here. I was attempting to upgrade my PIX OS. I have my PC connected directly to the inside interface of my PIX 515 with a crossover cable. I reloaded the PIX into "monitor" mode and named the interface and gave it an ip address. From this point on, I was not able to ping the PC from the PIX. However, I can ping the PIX from the PC. So, I reloaded the PIX in normal mode and still have the same problem. I can ping the PIX from my PC, but cannot ping my PC from the PIX. I have no personal firewall SW on my PC or anything.

PIX--------------------PC

I must be losing my mind here!

Thanks!

5 Replies 5

shannong
Level 4
Level 4

How do you have your pix setup for ICMP access?

show icmp

Does the firewall pass traffic outside for your PC?

Which interface are you using? I've heard stories of old NICs that aren't supported after an upgrade because their chipset is so old. I believe these to be add-in PCI NICs and not the on-board interfaces.

I am permitting icmp echo and echo-reply traffic on the inside interface. This is strange because all was working just great until I brought it up into "monitor" mode. That is when the ping problem started. I was not even able to upgrade the code. I am still using 6.1(3). I have completely blew the config out and am working with the bare bones config with an IP address on the inside interface.

I even changed to another PC for a sanity check. Still able to ping from PC to PIX, but not PIX to PC.

Maybe this is my hint to look into another career field. Is Starbucks hiring? :)

Thanks!!!

Use [icmp permit any any inside] to rule out human error in the configuration.

What does the logging buffer say when you're trying to ping?

logging buffered 7

show log

Also, you can use deb icmp packet. What's that say when you're trying to ping?

To clarify, you can ping the Pix from the PC but not in the other direction?

show arp MACs as expected?

Why were you using monitor mode to upgrade? Was there some other problem to start with? There's no need to use monitor mode with 6.1.3.

copy tftp flash:

Why don't you go ahead and upgrade the code?

-S

I have added all the necessary icmp statements to the config. I inserted a catalyst switch in between my pc and the PIX. I can ping from the PIX to the mgmt interface of the catalyst, but still unable to ping PIX to PC. I am not able to perform a "copy tftp flash" because I have no connectivity to the PC (TFTP server) from the PIX.

I am able to access the internet without a problem via the PIX and can even VPN into the PIX from the internet.

Too weird!!

Sounds like it's your PC then. What OS? Don't forget that XP has a firewall built in. There must be something on the PC preventing it from connecting/pinging.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card