Hi!
 
See http://www.cisco.com/warp/customer/110/31.html
 
 
According to this document "Inbound ICMP through the PIX is denied by
default; outbound ICMP is permitted, but the incoming reply is denied by
default." So you can ping every PIX interface from the PIX and from the
directly connected LAN, but can't ping through the pix.
 
I think you should not ping through the PIX default, just from the PIX (from
Telnet console).
 
According to this document: "In PIX Software versions 4.1(6) until 5.2.1,
ICMP traffic to the PIX's own interface is permitted; the PIX cannot be
configured to not respond. Beginning in PIX Software version 5.2.1, ICMP is
still permitted by default, but PIX ping responses from its own interfaces
can be disabled with the icmp command (that is, a "stealth PIX")"
 
 
By, HT




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=40928&t=40928
--------------------------------------------------
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

Reply via email to