Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Attn: Walter

Reply
Thread Tools

Attn: Walter

 
 
Rob
Guest
Posts: n/a
 
      10-19-2004

"Walter Roberson" <(E-Mail Removed)-cnrc.gc.ca> wrote in message
news:cl3akc$6lj$(E-Mail Removed)...
> In article <41752ae4$(E-Mail Removed)>, Rob <(E-Mail Removed)> wrote:
> :I am configuring a 515e (6.3) and having problem with enabling ping.
> :I have added:
> :icmp permit any echo outside
> :icmp permit any echo-reply outside
> :icmp permit any echo inside
> :icmp permit any echo-reply inside
>
> Those control what icmp is permitted to the PIX itself and have
> nothing to do with what is permitted *through* the PIX.
>
> :conduit permit icmp any any
>
> That permits all inbound icmp, I think.
>
>
> :However still ping doesnt work, (Firewall, Internet access works fine),

does
> :anyone know how to enable ping on this box.
>
> Do you have access controls applied to your inside interface? If so
> then my thought is that you aren't allowing the outbound icmp echo
> packets needed for ping.
>
> If you do not have access controls applied to your inside interface,
> then I cannot help you any further. The 'conduit' command was
> deprecated as of PIX 5.2.1, and will not be available in the
> next major software release, the now late PIX 7.0. Cisco indicates
> in the release notes that conduit is broken in some cases, and that
> as of PIX 6.2.1 there are known problems with conduit which will
> not be fixed. It is thus my policy not to assist in debugging
> configurations that have 'conduit' commands in them: there is,
> to my mind, no point in spending time trying to figure out why
> the configuration might be failing when the problem might be
> a PIX bug.
>
> If you revise your configuration to use purely the access-list/
> access-group model and the problem still occurs, then we are
> more likely to be able to help you.
> --
> This is not the same .sig the second time you read it.



I removed the condu and added access-list, however still cannot ping the
outside.

PIX(config)# access-list 120 permit icmp any any
PIX(config)# access-gro 120 in inter outs
PIX(config)# access-gro 120 in inter insi
Thanks again-Rob



 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
walter , did I do this right ? Barret Bonden Cisco 1 07-13-2005 09:10 PM
A question for Walter :-) Richard Graves Cisco 0 04-24-2005 03:37 AM
Juniper and Cisco Routing: Policy and Protocols for Multivendor Networks by Walter J. Goralski Ivan Ostreš Cisco 3 03-10-2005 06:03 AM
Attn: Walter Roberson Jem Berkes Cisco 1 12-12-2004 10:09 AM
Walter Roberson...HELP! BitBucket Cisco 5 10-23-2003 01:42 PM



Advertisments