Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX OS Upgrade problems (unable to ping)

My problems have been snowballing here. I was attempting to upgrade my PIX OS. I have my PC connected directly to the inside interface of my PIX 515 with a crossover cable. I reloaded the PIX into "monitor" mode and named the interface and gave it an ip address. From this point on, I was not able to ping the PC from the PIX. However, I can ping the PIX from the PC. So, I reloaded the PIX in normal mode and still have the same problem. I can ping the PIX from my PC, but cannot ping my PC from the PIX. I have no personal firewall SW on my PC or anything.


I must be losing my mind here!



Re: PIX OS Upgrade problems (unable to ping)

How do you have your pix setup for ICMP access?

show icmp

Does the firewall pass traffic outside for your PC?

Which interface are you using? I've heard stories of old NICs that aren't supported after an upgrade because their chipset is so old. I believe these to be add-in PCI NICs and not the on-board interfaces.

New Member

Re: PIX OS Upgrade problems (unable to ping)

I am permitting icmp echo and echo-reply traffic on the inside interface. This is strange because all was working just great until I brought it up into "monitor" mode. That is when the ping problem started. I was not even able to upgrade the code. I am still using 6.1(3). I have completely blew the config out and am working with the bare bones config with an IP address on the inside interface.

I even changed to another PC for a sanity check. Still able to ping from PC to PIX, but not PIX to PC.

Maybe this is my hint to look into another career field. Is Starbucks hiring? :)



Re: PIX OS Upgrade problems (unable to ping)

Use [icmp permit any any inside] to rule out human error in the configuration.

What does the logging buffer say when you're trying to ping?

logging buffered 7

show log

Also, you can use deb icmp packet. What's that say when you're trying to ping?

To clarify, you can ping the Pix from the PC but not in the other direction?

show arp MACs as expected?

Why were you using monitor mode to upgrade? Was there some other problem to start with? There's no need to use monitor mode with 6.1.3.

copy tftp flash:

Why don't you go ahead and upgrade the code?


New Member

Re: PIX OS Upgrade problems (unable to ping)

I have added all the necessary icmp statements to the config. I inserted a catalyst switch in between my pc and the PIX. I can ping from the PIX to the mgmt interface of the catalyst, but still unable to ping PIX to PC. I am not able to perform a "copy tftp flash" because I have no connectivity to the PC (TFTP server) from the PIX.

I am able to access the internet without a problem via the PIX and can even VPN into the PIX from the internet.

Too weird!!


Re: PIX OS Upgrade problems (unable to ping)

Sounds like it's your PC then. What OS? Don't forget that XP has a firewall built in. There must be something on the PC preventing it from connecting/pinging.