Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Pinging Pix Interfaces

Status
Not open for further replies.

adubla

Technical User
Apr 18, 2001
11
0
0
US
Pix520 with 3 interfaces. Access lists are set up for each interface with permit icmp any any. From the inside I can ping all of the DMZ servers, but I can not ping the Pix DMZ interface.

I need to be able to ping the DMZ interface and the Outside interface from the Inside interface. How could I set that up?

Thanks,

Alan
 
I appreciate the effort, but that didn't work.
 
Have u set up statics in ur config?
Ensure you have unique security values for each int and that the inside is 100 (ie max) then use a static statement inside to ur dmz int
 
I have security numhers assigned to all 3 of the interfaces. I have set up statics and tried that route, but it didn't work either. On that line, the docs seem to indicate that higher security interfaces may access those with lower security without defining additional statics. I'm trying to ping the DMZ and Outside interfaces from the inside. I can ping machines on the DMZ and machines on the Outside, just not the actual Pix DMZ and Outside interfaces themselves.

Thanks,

Alan
 
It will not work. Never.
Pix doesn't route a packet to the interface that came for.
In this case. ICMP echo-request came from inside interface and go to destination dmz interface. This one change the bit to echo-reply. But cannot send the pachet back to inside interface because the pachet came from this interface.
So, you'll never get echo-replay pachet.
It's a security measure. And it's correct.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top