Cisco PIX 525 Spezifikationen Seite 83

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 466
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 82
2-23
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 2 Establishing Connectivity
Testing and Saving Your Configuration
Testing Connectivity
You can use the access-list command to allow hosts on one interface to ping through to hosts on another
interface. This lets you test that a specific host is reachable through the PIX
Firewall.
The ping program sends an ICMP echo request message to the IP address and then expects to receive an
ICMP echo reply. The ping program also measures how long it takes to receive the reply, which you can
use to get a relative sense of how far away the host is.
Note We recommend that you only enable pinging during troubleshooting. When you are done testing the
interfaces, remove the ICMP access-list command statements.
To test your connectivity, perform the following steps:
Step 1 Start with a sketch of your PIX Firewall, with each interface connected to the inside, outside, and any
perimeter networks.
Figure 2-4 shows an example sketch:
Figure 2-4 Sketch a Network with Interfaces and Routers
34788
dmz1
192.168.1.1
security20
dmz3
192.168.3.1
security60
dmz4
192.168.4.1
security80
dmz2
192.168.2.1
security40
outside
209.165.201.1
security0
inside
192.168.0.1
security100
PIX Firewall
Router
209.165.201.2
Router
192.168.0.2
Router
192.168.4.2
Router
192.168.3.2
Router
192.168.2.2
Router
192.168.1.2
Step 2 Enable Pinging.
Enter an access-list command to permit ICMP access as follows:
access-list acl_out permit icmp any any
The “acl_out” is an access-list command ID and can be any name or a number you specify. Use the show
access-list command to view this command in the configuration.
You then need to specify an access-group command for each interface through which you want the
ICMP packets to pass. Use the show access-group command to view this command in the configuration.
Seitenansicht 82
1 2 ... 78 79 80 81 82 83 84 85 86 87 88 ... 465 466

Kommentare zu diesen Handbüchern

Keine Kommentare