Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ICMP with NAT Exemption?

Status
Not open for further replies.
Apr 3, 2003
180
US
Here I go again with ICMP questions, anyway I have a PIX with 3 Interface's

outside 200.200.200.1
inside 192.168.1.0
dmz 192.168.2.0

I run the following access-list to disable NAT between the inside and dmz interfaces's.

access-list NO_NAT permit ip 192.168.1.0/24 192.168.2.0/24
nat (inside) 0 access-list NO_NAT

This NAT exemption works fine but I am having a hard time permitting icmp trafic between these networks. I have tried diffrent access-list's and static translations but I cannot get it to work. I have no problem with icmp when nat is involved but I think NAT exemption requires a diffrent thought process. Any help is much appreciated.
By the way this pix is running FOS 7.X and I know about the ICMP INSPECT modification to the default service policy, but I still want to know how to permit icmp with NAT exemption.

"I hear and I forget. I see and I remember. I do and I understand."
- Confucius (551 BC - 479)
 
access-list dmz permit icmp any any echo reply

access-group dmz in interface dmz

In addition most people use a static nat for access to the dmz from the inside instead of nat exemption.

static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top