hello,
there are to issues you have to handle,
1) deny that the pix answeres to pings
2) deny that ping-requests (icmp, or what ever) goes through the pix to an internal server.
1)
To solve this you must make a icmp deny outside.
Please make a show icmp on the pix and give us the output.
if you make several icmp command, the icmp-deny/permit rules will be checked in a top-down way on the pix (i hope you understand what i mean).
so if you have a
icmp permit any any
icmp deny any outside
--> You can ping the pix
2)
As i sad, you have to block this with an access-list. But if you do not allow it, it will be blocked.
Martin
----------------------------------
Martin Peinsipp, Austria
CCSA,
IT-Security-Administrator