RE: [fw-wiz] Ping between PIX remote peers



V7 allows the PIX to send traffic out an interface that it came in on IF
it is configured to do so. Otherwise, the traffic is still dropped and
not allowed.

-----Original Message-----
From: Brian Loe [mailto:knobdy@xxxxxxxxx]
Sent: Thursday, May 04, 2006 9:31 AM
To: Utz, Ralph
Cc: Juan Pablo Feria Gomez; firewall-wizards@xxxxxxxxxxxxxxxxxx
Subject: Re: [fw-wiz] Ping between PIX remote peers

What happens in v7? I'll assume for now they've just built in the
aliasing for requests coming in on the inside port, right? Like
presumably a SonicWall does?

Surely they're not breaking security by allowing this to happen with
no checks...

On 5/3/06, Utz, Ralph <rutz@xxxxxxxxxxxxxxx> wrote:
"PIX will not send traffic out the same interface it came in on"

Applies to all versions of PIX IOS less than v7

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Interesting problem with pix 515 UR
    ... Consider diabling Proxy arp on inside interface. ... This pix have only 2 ethernet interfaces; i have connected the ethernet0via a cross cable ... fixup protocol dns maximum-length 512 ... ntp server 194.100.206.70 source outside ...
    (comp.dcom.sys.cisco)
  • Interesting problem with pix 515 UR
    ... This pix have only 2 ethernet interfaces; i have connected the ethernet0via a cross cable ... interface FastEthernet0/21 ... fixup protocol dns maximum-length 512 ... ntp server 194.100.206.70 source outside ...
    (comp.dcom.sys.cisco)
  • Re: One internal network, VPN, 2 PIX
    ... all I can ping is the internal interface on the PIX that I'm VPN'ing in to. ... Do I need to add ACL's into the Corp PIX to allow the VPN traffic (I already ... the 192.168.200.* inside hosts, the inside hosts are going to ... so the interior hosts send responses to the 501); ...
    (comp.dcom.sys.cisco)
  • [fw-wiz] Double firewall setup (long)
    ... One PIX 515E w/ 3 interfaces: inside, outside, DMZ. ... access-list OUTB permit tcp 10.181.8.0 255.255.248.0 any eq www ... interface ethernet0 auto ...
    (Firewall-Wizards)
  • Re: Cisco PIX 501: Cant ping global IP-Adress from NATed IP
    ... on the 'static' statement for the server, add the 'dns' keyword. ... The catch is that the two interfaces cannot have the same IP subnet, ... of the external interface. ... then the PIX wouldn't know which interface to send it towards. ...
    (comp.dcom.sys.cisco)