received, the proper operation of any intermediate devices and physical connectivity is confirmed.
Troubleshooting Operation of the Ping Tool
When pings fail to receive an echo, it may be the result of a configuration or operational error in a PIX Firewall
unit, and not always due to "NO response" from the IP address being pinged. Before using the Ping tool to ping
from, to or through a PIX Firewall interface, verify the following:
Basic interface checks
Verify that interfaces are configured properly in
System Properties>Interfaces
and/or using the CLI
show interfaces command from
PDM Tools>CLI.
❍
Check each interface physically for good mechanical and electrical connectivity—cables are
connected, link indicators are green, and any passive devices, such as hubs are operational.
❍
Verify that devices in the intermediate communications path, such as switches or routers, are
properly delivering other types of network traffic.
❍
Make sure that traffic of other types from "known good" sources is being passed. Use the show
interface command from the
PDM CLI tool
or PDM Monitoring>Interface Graphs.
❍
●
Pinging from a PIX Firewall interface—For basic testing of an interface, a ping may be initiated from a
PIX Firewall interface to a network device which, by other means, is known to be functioning properly and
returning echoes via the intermediate communications path.
Verify receipt of the ping from the PIX Firewall interface by the "known good" device. If it is not
received, there may be a problem with the transmit hardware or configuration of the interface.
❍
If the PIX Firewall interface is configured properly and it does not receive an echo from the "known
good" device, there may be problems with the interface hardware receive function. If a different
interface with "known good" receive capability can receive an echo after pinging the same "known
good" device, the hardware receive problem of the first interface is confirmed.
❍
●
Pinging to a PIX Firewall interface—When attempting to ping to a PIX Firewall interface, verify that
pinging response (ICMP echo reply), is enabled for that interface in the
System Properties>PIX
Administration>ICMP
panel. When pinging is disabled, the PIX Firewall cannot be detected by other
devices or software applications, and will not respond to the PDM Ping tool.
●
Pinging through the PIX Firewall
First, verify that other types of network traffic from "known good" sources is being passed through
through the PIX Firewall unit. Use Monitoring>Interface Graphs, or an SNMP management
station.
❍
To enable internal hosts to ping external hosts, ICMP access must be configured correctly for both
the inside and outside interfaces in Access Rules.
❍
Refer to the Cisco Secure PIX Firewall Configuration Guide for more information on pinging
through the PIX Firewall.
❍
●
Copyright © 2001
Cisco Systems, Inc.
Содержание PIX 520 - PIX Firewall 520
Страница 45: ...Copyright 2001 Cisco Systems Inc ...
Страница 68: ...Copyright 2001 Cisco Systems Inc ...
Страница 74: ...Copyright 2001 Cisco Systems Inc ...
Страница 87: ...Copyright 2001 Cisco Systems Inc ...
Страница 92: ...Copyright 2001 Cisco Systems Inc ...
Страница 107: ...The panel has these buttons OK Exits the panel Help Provides more information Copyright 2001 Cisco Systems Inc ...
Страница 108: ......
Страница 184: ......
Страница 197: ...Copyright 2001 Cisco Systems Inc ...
Страница 200: ......
Страница 232: ...Copyright 2001 Cisco Systems Inc ...
Страница 246: ...Copyright 2001 Cisco Systems Inc ...