PIX configuration manual 4 (icmp global configuration)
PIX configuration manual 4 (icmp global configuration)
By default, PIX allows directly connected devices to ping the interface of pix, but does not allow any interface that traverses pingPIX.
Indirect ping through PIX can be controlled by acl.
If you do not want others to pingPIX the interface, pix can go to ping others, you can use icmp to control.
Use the following command:
Icmp deny any echo outside blocks eho traffic coming in from outside pix, preventing others from ping themselves
Icmp permit any outside allows any icmp traffic coming in from outside to ensure that it can go to ping others.
Icmp deny any echo inside blocks eho traffic coming in from within pix, preventing others from ping themselves
Icmp permit any inside allows any internal icmp traffic to ensure that it can go to ping others.
Of course, icmpdeny any can be done according to the actual situation with other parameters. The following parameters
Alternate-address
Conversion-error
Echo
Echo-reply
Information-reply
Information-request
Mask-reply
Mask-request
Mobile-redirect
Parameter-problem
Redirect
Router-advertisement
Router-solicitation
Source-quench
Time-exceeded
Timestamp-reply
Timestamp-request
Traceroute
Unreachable