I don't understand why I can not ping the outside PIX interface and local router from an internal client. Any ideas?
Here is my config info ...
# show ip
System IP Addresses:
ip address outside n.n.n.15 255.255.255.224
ip address inside 192.168.100.100 255.255.255.0
Current IP Addresses:
ip address outside n.n.n.15 255.255.255.224
ip address inside 192.168.100.100 255.255.255.0
# show nat
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
# show global
global (outside) 1 n.n.n.14 netmask 255.255.255.224
# show access-list
access-list acl_out permit icmp any any (hitcnt=0)
# show access-group
access-group acl_out in interface outside
#show route
outside 0.0.0.0 0.0.0.0 n.n.n.1 1 OTHER static
outside n.n.n.0 255.255.255.224 n.n.n.15 1 CONNECT static
inside 192.168.100.0 255.255.255.0 192.168.100.100 1 CONNECT static
Ping Debug: From client at 192.168.100.111 on internal side
Pinging PIX inside interface 192.168.100.100 works fine
29: ICMP echo request (len 32 id 2 seq 21504) 192.168.100.111 > 192.168.100.100
30: ICMP echo reply (len 32 id 2 seq 21504) 192.168.100.100 > 192.168.100.111
Pinging PIX outside interface n.n.n.15 doesn’t work
37: Outbound ICMP echo request (len 32 id 2 seq 22528) 192.168.100.111 > n.n.n.14 > n.n.n.15
38: Outbound ICMP echo request (len 32 id 2 seq 22784) 192.168.100.111 > n.n.n.14 >n.n.n.15
Pinging outside the PIX but local ip n.n.n.25 works fine
74: Outbound ICMP echo request (len 32 id 2 seq 27648) 192.168.100.111 > n.n.n.14 > n.n.n.25
75: Inbound ICMP echo reply (len 32 id 3328 seq 27648) n.n.n.25 > n.n.n.14 > 92.168.100.111
Pinging outside the PIX to the local router n.n.n.1 doesn’t work
82: Outbound ICMP echo request (len 32 id 2 seq 28672) 192.168.100.111 > n.n.n.14 > n.n.n.1
83: Outbound ICMP echo request (len 32 id 2 seq 28928) 192.168.100.111 > n.n.n.14 > n.n.n.1
Ping Debug: From PIX
Ping the outside local router works fine
# ping n.n.n.1
71: ICMP echo reply (len 32 id 9233 seq 0) n.n.n.1 > n.n.n.15
72: ICMP echo reply (len 32 id 9233 seq 1) n.n.n.1 > n.n.n.15
73: ICMP echo reply (len 32 id 9233 seq 2) n.n.n.1 > n.n.n.15
n.n.n.1 response received -- 0ms
n.n.n.1 response received -- 0ms
n.n.n.1 response received -- 0ms
Here is my config info ...
# show ip
System IP Addresses:
ip address outside n.n.n.15 255.255.255.224
ip address inside 192.168.100.100 255.255.255.0
Current IP Addresses:
ip address outside n.n.n.15 255.255.255.224
ip address inside 192.168.100.100 255.255.255.0
# show nat
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
# show global
global (outside) 1 n.n.n.14 netmask 255.255.255.224
# show access-list
access-list acl_out permit icmp any any (hitcnt=0)
# show access-group
access-group acl_out in interface outside
#show route
outside 0.0.0.0 0.0.0.0 n.n.n.1 1 OTHER static
outside n.n.n.0 255.255.255.224 n.n.n.15 1 CONNECT static
inside 192.168.100.0 255.255.255.0 192.168.100.100 1 CONNECT static
Ping Debug: From client at 192.168.100.111 on internal side
Pinging PIX inside interface 192.168.100.100 works fine
29: ICMP echo request (len 32 id 2 seq 21504) 192.168.100.111 > 192.168.100.100
30: ICMP echo reply (len 32 id 2 seq 21504) 192.168.100.100 > 192.168.100.111
Pinging PIX outside interface n.n.n.15 doesn’t work
37: Outbound ICMP echo request (len 32 id 2 seq 22528) 192.168.100.111 > n.n.n.14 > n.n.n.15
38: Outbound ICMP echo request (len 32 id 2 seq 22784) 192.168.100.111 > n.n.n.14 >n.n.n.15
Pinging outside the PIX but local ip n.n.n.25 works fine
74: Outbound ICMP echo request (len 32 id 2 seq 27648) 192.168.100.111 > n.n.n.14 > n.n.n.25
75: Inbound ICMP echo reply (len 32 id 3328 seq 27648) n.n.n.25 > n.n.n.14 > 92.168.100.111
Pinging outside the PIX to the local router n.n.n.1 doesn’t work
82: Outbound ICMP echo request (len 32 id 2 seq 28672) 192.168.100.111 > n.n.n.14 > n.n.n.1
83: Outbound ICMP echo request (len 32 id 2 seq 28928) 192.168.100.111 > n.n.n.14 > n.n.n.1
Ping Debug: From PIX
Ping the outside local router works fine
# ping n.n.n.1
71: ICMP echo reply (len 32 id 9233 seq 0) n.n.n.1 > n.n.n.15
72: ICMP echo reply (len 32 id 9233 seq 1) n.n.n.1 > n.n.n.15
73: ICMP echo reply (len 32 id 9233 seq 2) n.n.n.1 > n.n.n.15
n.n.n.1 response received -- 0ms
n.n.n.1 response received -- 0ms
n.n.n.1 response received -- 0ms