Hi all,
I am new to PIX FW, my company,only 30 hosts, switch from fractional T1 to Dsl w/static IPs, the PIX works fine for frame relay, but the problem now is the T1 router is removed from outside, the current connection is the PIX direct connect to outside. from the PIX is able to ping any inside and outside host without any problem, but inside hosts is not able to ping outside.
I am search cisco website and not been able to get a sample configuration on the similar situation, direct to ISP w/o a router. so could anyone help or a configuration sample is very welcome and appreciated.
here are some config lines, note the rest of the command are default config from the PIX
-----------------------
ip address outside 66.xx.xxx.14 255.255.255.240
ip address outside 10.100.xx.4 255.255.255.0
global (outside) 1 66.xx.xxx.6-66.xx.xxx.13 netmask 255.255.255.240
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside, outside) 66.xx.xxx.2 10.100.xx.2 netmask 255.255.255.255 0 0
static (inside, outside) 66.xx.xxx.3 10.100.xx.3 netmask 255.255.255.255 0 0
conduit permit icmp any any echo
conduit permit icmp any any echo-relay
route outside 0.0.0.0 0.0.0.0 66.13.137.1 1
route inside 10.100.xx.0 255.255.255.0 10.100.xx.255 1
Thanks,
Dennis
I am new to PIX FW, my company,only 30 hosts, switch from fractional T1 to Dsl w/static IPs, the PIX works fine for frame relay, but the problem now is the T1 router is removed from outside, the current connection is the PIX direct connect to outside. from the PIX is able to ping any inside and outside host without any problem, but inside hosts is not able to ping outside.
I am search cisco website and not been able to get a sample configuration on the similar situation, direct to ISP w/o a router. so could anyone help or a configuration sample is very welcome and appreciated.
here are some config lines, note the rest of the command are default config from the PIX
-----------------------
ip address outside 66.xx.xxx.14 255.255.255.240
ip address outside 10.100.xx.4 255.255.255.0
global (outside) 1 66.xx.xxx.6-66.xx.xxx.13 netmask 255.255.255.240
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside, outside) 66.xx.xxx.2 10.100.xx.2 netmask 255.255.255.255 0 0
static (inside, outside) 66.xx.xxx.3 10.100.xx.3 netmask 255.255.255.255 0 0
conduit permit icmp any any echo
conduit permit icmp any any echo-relay
route outside 0.0.0.0 0.0.0.0 66.13.137.1 1
route inside 10.100.xx.0 255.255.255.0 10.100.xx.255 1
Thanks,
Dennis