Cisco Support Community

The Internet is not accessible with the PIX Firewall and the "No route to dest_addr from src_addr" error message appears

Core issue

This issue occurs because a default route does not exist on the Cisco Secure PIX Firewall, or because NATting/PATting is not configured.


In order to resolve this issue, complete these steps:

  1. Make sure the PIX has the route outside command configured in order to direct all unknown traffic to the directly connected Ethernet port of the outside router.

  2. Verify that the default gateway of the client is set to the inside interface of the PIX.

  3. For pings to work, verify that there is an access-list statement applied to the outside interface that permits the Internet Control Message Protocol (ICMP) echo-replies back in through the PIX.

  4. Verify that the PIX configuration has a translation, either a nat and a related global statement or a static statement, for the inside host. In order to check the translation, issue the show xlate command.

      For example, in order to translate the network on the inside interface, enter these commands:

   hostname(config)#nat (inside) 1
   hostname(config)#global (outside) 1

     In order to identify a pool of addresses for dynamic NAT as well as a PAT address for when the NAT pool is exhausted, enter these commands:

   hostname(config)#nat (inside) 1
   hostname(config)#global (outside) 1
   hostname(config)#global (outside) 1

     Refer to the Cisco Secure PIX Firewall Command References of the appropriate software version for more information about these PIX commands.