News: This forum is now permanently frozen.
Pages: [1]
Topic: Can't ping WAN ip from LAN ip  (Read 5111 times)
« on: March 17, 2007, 17:51:37 »
sabo *
Posts: 2

 Huh

I have a brand new install.  This is a test install to learn the basics.  I can create port forwarding that I can forward to my DMZ from outside of the WAN IF.  But when I try to ping out the WAN from the LAN no luck.   I cant ping any of the 4 interfaces that I have on the box from the LAN. 

Should I be able to ping any of the interface IP's that I have in the box from the LAN with the default install config Huh?
Do I need to create rules for this to happen?
« Reply #1 on: March 17, 2007, 21:08:11 »
sigterm *
Posts: 1

You definetely should be able to ping the LAN IP of the m0n0 box from your LAN subnet.  You can start see'ing whats going on by checking the firewall log entries and seeing where its getting blocked at.  By default, I believe, you can do this with no editing of the firewall rulesets.

The default ruleset for the LAN subnet is:  any protocol from LAN subnet, on any port, to any destination to any port.  So basically, anything goes for the LAN subnet.  Check your configs and see whats going on with it.

-sigterm
« Reply #2 on: March 17, 2007, 22:34:20 »
Lee Sharp *****
Posts: 517

You can not ping natted services from the LAN.  This is a design limitation.  You need to ping the DMZ systems using the real IP addresses of those systems.
« Reply #3 on: March 20, 2007, 04:32:09 »
falcor *
Posts: 17

You can not ping natted services from the LAN.  This is a design limitation.  You need to ping the DMZ systems using the real IP addresses of those systems.

Actually it is done correctly, not a limitation.  And pinging things on your DMZ assumes you are allowing ICMP between your LAN and DMZ (OPT1) inteface.  So yes, a rule might need to be setup.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines