Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

simple testing configuration access-list question

Status
Not open for further replies.

catatung

Technical User
Oct 20, 2003
10
US
Hello,

I am trying to write up a configuration to test PIX firewalls. I have a pix 515 which I have networked into a hub with two other computers. I am trying to display it's ability to refuse connections. I can ping it from one machine and I can ping the machine from it.. I put in the access-list:

access-list all deny ICMP any any

but I can still ping the machine from the firewall and I can still ping the firewall from the machine. Shouldn't pings not be responded to with that rule? and If I have this wrong, what can I use to prove the firewall has the ability to refuse certain connections? I have linux redhat 9.0 on one machine and win NT server on the other.

any help would is appreciated
thanks
-Randy
 
Hey thanks I got it working....

How come that command doesn't work though? In theory, shouldn't it?
 
Nope it should not work, the access list entry for ICMP works only for traffic passing through the PIX and not to the PIX. For ICMP traffic to the PIX´s interface you need the "icmp ..." command.
 
ah.. i see it now
thanks for the help!

-=Randy
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top