Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: no ping reply |
|---|---|
| Date: | Tue, 28 Feb 2006 12:08:09 -0300 |
With "sh log", Albert wanted to see the FW logging... If it is logging to a syslog, I think you should show us the logging records of the syslog.... ¬¬ __________________________________________________ Pablo D. Hauser | pH www.securearg.net Secure from the source -----Mensaje original----- De: Imran Imtiaz [mailto:imran@thelakecity.com.pk] Enviado el: Sábado, 25 de Febrero de 2006 02:19 Para: Albert Tuulas CC: firewalls@securityfocus.com Asunto: Re: no ping reply here is what "show log" shows pixfirewall(config)# show log Syslog logging: enabled Facility: 20 Timestamp logging: disabled Standby logging: disabled Console logging: disabled Monitor logging: disabled Buffer logging: disabled Trap logging: disabled History logging: disabled Device ID: disabled and below is what debug icmp trace shows pixfirewall(config)# debug icmp trace ICMP trace on Warning: this may cause problems on busy networks pixfirewall(config)# 115: ICMP echo-request from inside:192.168.1.3 to 192.168.0 .9 ID=512 seq=27904 length=40 116: ICMP echo-request: translating inside:192.168.1.3/512 to outside:192.168.0. 9/0 117: ICMP echo-request from inside:192.168.1.3 to 192.168.0.9 ID=512 seq=28160 length=40 118: ICMP echo-request: translating inside:192.168.1.3/512 to outside:192.168.0.9/0 119: ICMP echo-request from inside:192.168.1.3 to 192.168.0.9 ID=512 seq=28416 length=40 120: ICMP echo-request: translating inside:192.168.1.3/512 to outside:192.168.0.9/0 currently i am pinging from a host (192.168.1.2) connect to the inside interface (192.168.1.1) of firewall to the outside interface (192.168.0.9) of firewall and no reply comes. below is my acl pixfirewall(config)# show access-list access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 256) alert-interval 300 access-list acl_out; 3 elements access-list acl_out line 1 permit tcp any any (hitcnt=4) access-list acl_out line 2 permit udp any any (hitcnt=70) access-list acl_out line 3 permit icmp any any (hitcnt=4) access-list acl_in; 3 elements access-list acl_in line 1 permit tcp any any (hitcnt=676) access-list acl_in line 2 permit udp any any (hitcnt=197) access-list acl_in line 3 permit icmp any any (hitcnt=141) pixfirewall(config)# show access-group access-group acl_out in interface outside access-group acl_in in interface inside pixfirewall(config)# and nat configs pixfirewall(config)# show global global (outside) 1 interface pixfirewall(config)# show nat nat (inside) 1 0.0.0.0 0.0.0.0 0 0 pixfirewall(config)# ----- Original Message ----- From: "Albert Tuulas" <albert@cubio.fi> To: "Imran Imtiaz" <imran@thelakecity.com.pk> Cc: <firewalls@securityfocus.com> Sent: Friday, February 24, 2006 11:28 PM Subject: Re: no ping reply
Do you have NAT rules configured? Seems to be NAT misconfigured. Albert What does 'show log' and 'debug icmp trace' give when you ping inside 192.168.1.1 from 192.168.1.2? AlbertI have cisco pix 501 firewall the ip of outside interface is 192.168.0.9 and inside interface is 192.168.1.1. i have opened icmp on outside and inside interfaces. Now when i ping 192.168.1.1 from a client having ip 192.168.1.2 no ping reply com how ever if i ping the router attached to the outside interface replys come. where is the problem?the securiting level of outside is 0 and inside is 100regards,imran imtiaz
___________________________________________________________
1GB gratis, Antivirus y Antispam
Correo Yahoo!, el mejor correo web del mundo
http://correo.yahoo.com.ar
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: no ping reply, Jalal Bouhdada |
|---|---|
| Next by Date: | RE: Open source windows firewall, Nguyen, PB |
| Previous by Thread: | Re: no ping reply, Imran Imtiaz |
| Next by Thread: | Re: no ping reply, Jalal Bouhdada |
| Indexes: | [Date] [Thread] [Top] [All Lists] |