Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 501 - Traffic not getting out

Status
Not open for further replies.

adarmus

Technical User
Sep 8, 2006
7
GB
I need to access hosts on a remote LAN via a router that has been installed locally.
(The configuration of the router is managed by someone else and I have no access to it.)
I can connect OK (and can ping remote hosts etc.) if I wire up a PC directly to the local router configured with:
IP address: <X>
Gateway: <R>
Subnet: 255.255.255.224

Works: Remote LAN --- Router --- PC

However, when I put a PIX 501 between my LAN and the router I cannot connect to the
remote LAN from my local LAN, even though I can ping hosts on the remote LAN from the PIX.

Fails: Remote LAN --- Router --- PIX --- PC

I have set the PIX outside IP address and a default static route:
ip address outside <X> 255.255.255.224
route outside 0.0.0.0 0.0.0.0 <R> 1

and configured the PC to use the PIX as its gateway (I can ping the PIX from the PC).

But I have had no success. Do I need to set up an ACL entry?
But I thought all outbound traffic was allowed?
Thanks for any help you can give me.
 
For ping, yes. You're not allowing ICMP to come in from the untrusted network to the trusted side.

Also check your address translation. If you just plugged it in out of the box, that should be ok.

If you have something else to try, like web traffic, you'll probably find that it already works.
 
icmp is not stateful, so you need to allow to allow icmp on the outbound interface
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top