just give the following commands... access-list acl-in permit icmp any any access-list acl-out permit icmp any any access-group acl-in in interface inside access-group acl-out in interface outside
I gave two access-lists to distinguish between inside and outside traffic. This will allow ping and traceroute in both directions. But remember PIX interfaces will not showup in the traceroute. Hope this helps regards Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=55488&t=55470 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

