Re: PIX to PIX: new subnet cannot ping to other side



RLM wrote:
Hi Guys,

http://www.xs4all.nl/~dbolderm/Tekening1.jpg

I have 2 PIX's inplace. One end is a 192.168.1.x and 192.168.2.x
network, the other end is a 192.168.3.x network.

Ping/Acess to/from both sides is ok.

Now I've installed an ISA2004 on the 192.168.1.x network. This server
has a NIC with a 192.168.4.0 network. From this network I am unable to
ping the 192.168.3.0 network. I think the problem is in the PIX setup,
but I am pretty sure I created the correct access lists, allowed ICMP,
etc.

Logging on the pix shows ICMP request, but no replies.

Even if you lost all the links in your picture, I can tell you you need to specify on both the interface which ICMP traffic is permitted. So don't treat ICP like udp or TCP, thinking to specified rules only on one side.

HTH

Alex.
.



Relevant Pages

  • Re: Removing ping/icmp from a network
    ... A ping sweep isn't the only way to do network exploration. ... ICMP is a protocol, not a service. ... Security by design is always best, but hiding the presence of a device ...
    (Security-Basics)
  • Re: How to prevent system from replying to Ping (ICMP Echo) requests?
    ... blocking ICMP does not impact anything useful ... large corporation broke their "VPN" by disallowing echo requests. ... > network from unknown locations, but, as I'm smarter than that, I set the ... The "stealth those pings" scenario would seem to really only ...
    (comp.security.firewalls)
  • Re: Removing ping/icmp from a network
    ... You can limit ICMP. ... And I did say, as well as others, allow from trusted sources. ... the network and the answer is: ... servers I do allow some ICMP messages to/from ...
    (Security-Basics)
  • Re: Ok to let all ICMP traffic through firewall?
    ... >>need to have ICMP responses form our networks get it, ... so now you are saying that you block outgoing ICMP ... > Tell me - what is the risk of sending an ICMP packet to anyone? ... it's not a general risk to your network because they ...
    (comp.security.firewalls)
  • Re: Ok to let all ICMP traffic through firewall?
    ... >>need to have ICMP responses form our networks get it, ... so now you are saying that you block outgoing ICMP ... > Tell me - what is the risk of sending an ICMP packet to anyone? ... it's not a general risk to your network because they ...
    (alt.computer.security)