Hi,
I have just installed a PIX 501 and I'm having an odd issue with PING that results in lost traffic. I am a newbie at PIX configuration so it could be a screw up on my part... ;-)
My set up is as follows
PIX 501, outside has one public IP address and performs translations for 2 others
The two inside servers have an address of 10.0.0.51 and 10.0.0.52 respectively. Outside connectivity to these machines via the translation works flawlessly with no packet loss etc..
However when I try and ping these two machines from within my inside network from another device, I receive soemthing like this
Pinging 10.0.0.52 with 32 bytes of data:
Reply from 10.0.0.52: bytes=32 time=2ms TTL=64 Request timed out. Reply from 10.0.0.52: bytes=32 time=1ms TTL=64 Reply from 10.0.0.52: bytes=32 time=1ms TTL=64
Ping statistics for 10.0.0.52: Packets: Sent = 4, Received = 3, Lost = 1 (25% loss), Approximate round trip times in milli-seconds: Minimum = 1ms, Maximum = 2ms, Average = 1ms
With ICMP tracing turned on I noticed the following within the pix
2907: ICMP echo-request from inside:10.0.2.1 to INSIDE_DQ ID=512 seq=42753 length=40 2908: ICMP echo-request: translating inside:10.0.2.1/512 to outside:X.X.X.X/60 2909: ICMP echo-request: untranslating inside:INSIDE_DQ to outside:OUTIP 2910: ICMP echo-request from inside:10.0.2.1 to INSIDE_DQ ID=512 seq=43777 length=40 2911: ICMP echo-request: translating inside:10.0.2.1/512 to outside:X.X.X.X/61 2912: ICMP echo-request: untranslating inside:INSIDE_DQ to outside:OUTIPWhich surprises me that the ICMP echo request is actually getting translated to the outside IP address. I can ping other machines on the inside network with out issue, its just the two machines that have a translation defined for them that have an issue. Also if I add another non translated IP address to the machines they also do not have an issue.
Any ideas on what could be going on in this situation, to cause the translation for the ICMP packets to kick in ?
Thanks
Wayne