Hi! See http://www.cisco.com/warp/customer/110/31.html According to this document "Inbound ICMP through the PIX is denied by default; outbound ICMP is permitted, but the incoming reply is denied by default." So you can ping every PIX interface from the PIX and from the directly connected LAN, but can't ping through the pix. I think you should not ping through the PIX default, just from the PIX (from Telnet console). According to this document: "In PIX Software versions 4.1(6) until 5.2.1, ICMP traffic to the PIX's own interface is permitted; the PIX cannot be configured to not respond. Beginning in PIX Software version 5.2.1, ICMP is still permitted by default, but PIX ping responses from its own interfaces can be disabled with the icmp command (that is, a "stealth PIX")" By, HT
Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=40928&t=40928 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]