Re: PIX 501 routing issues



On Fri, 29 Jun 2007 06:54:17 -0700, Justin wrote:

On Jun 28, 5:46 pm, Chris <mandrake...@xxxxxxxxxxx> wrote:
Internal devices (configured with the PIX as the gateway) can ping the
inside interface of the PIX but not the outside.

With a Pix you can only ping the closet IP address. You shouldn't be able
to ping the outside address from the inside. This is quite normal.

Chris.

Unfortunaltely, using ping and traceroute were just a tools to test
routing in an attempt to see why internet traffic could not make it
outside the PIX. I have tried resetting the box back to factory
defaults and using the 192.168.1.x ip address scheme and connecting
the outside interface directly to an internet router, setting up the
default NAT and allowing all traffic on both sides and it still will
not let a computer from the inside look outwards.

Tis probably time for a call to Cisco.

Your config looked okay. I presume that you checked the routing on the
client PC's? What did a "sh xlate" show on the pix? Could the clients
resolve URL's to IP's?

Chris.
.



Relevant Pages

  • Re: [fw-wiz] Pix VPN endpoint and split-tunnel
    ... forward the packet back out the same interface it was received. ... If you are running PIX OS 6.3., it is a correct statement that you ... >>would like to force the client to use the corporate network for ... >of anything the PIX or VPN client do. ...
    (Firewall-Wizards)
  • Re: Cient VPN full tunnel on a Pix
    ... Is it possible to do a full clinet VPN tunnel on a Pix? ... I am not sure what you mean by a "full client VPN tunnel". ... interface that the packets came in on. ...
    (comp.dcom.sys.cisco)
  • RE: [fw-wiz] Odd PIX / router behavior
    ... ISP's router one or two hops upstream from your Pix. ... locally defined since you cannot ping it when specifying the inside ... On a Pix 515 DMZ bundle the DMZ interface defaults to this ...
    (Firewall-Wizards)
  • Re: PIX 501 routing issues
    ... inside interface of the PIX but not the outside. ... With a Pix you can only ping the closet IP address. ...
    (comp.dcom.sys.cisco)
  • Re: PIX & XP
    ... firewall on its inside interface. ... default gateway on the machine points to the PIX. ... and connect via VPN to the PIX, they can ping themselves (for testing, ... VPN pool is ...
    (comp.dcom.sys.cisco)