<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 6509E Switch Vlan Issue in Switching</title>
    <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088849#M79675</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT works pretty much the same way it does on traditional Pix. Yes you can use &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 192.168.101.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which tells the FWSM not to NAT. You would only need a static if you wanted to initiate the connection from the outside to the 192.168.101.10 host - see previous post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad you got it working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 01 Nov 2008 18:50:55 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2008-11-01T18:50:55Z</dc:date>
    <item>
      <title>6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088830#M79656</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 6509E switch with FWSM. There is 2 valn for the fwsm also. inside vlan 101 and outside vla 95. Outside will be the virtual  connection to the MSFC for fwsm to msfc routing and on 101 vlan connects the server Farm, int gig1/1-40 on the same switch.&lt;/P&gt;&lt;P&gt;The Problem what i am facing now is - both my interfaces on the fwsm is showing down&lt;/P&gt;&lt;P&gt;int vlan 95 outside&lt;/P&gt;&lt;P&gt;down/down&lt;/P&gt;&lt;P&gt;int vlan 101 inside&lt;/P&gt;&lt;P&gt;down/down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I read in many places that you need a up/up interface or active trunk to make the SVI up. What i should do in thios case, if i want to conect the msfc to FWSM??? &lt;/P&gt;&lt;P&gt;also if i want to create a Managment SVI for the devices, i will not assign any port just for management access only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 10:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088830#M79656</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2019-03-06T10:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088831#M79657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I sugges you read the below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm22/configuration/guide/fwsm_cfg.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm22/configuration/guide/fwsm_cfg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 11:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088831#M79657</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-11-01T11:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088832#M79658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Andrew.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the Link&lt;/P&gt;&lt;P&gt;Sure, i will go through the file. i have configured up to this as of now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My connectivity is as follows- &lt;/P&gt;&lt;P&gt;ASA Inside -&amp;gt; connect to 6509E MSFC on int vlan 90 &lt;/P&gt;&lt;P&gt;==== &lt;/P&gt;&lt;P&gt;ASA 5540 &lt;/P&gt;&lt;P&gt;int vlan 90 &lt;/P&gt;&lt;P&gt;nameif inside &lt;/P&gt;&lt;P&gt;des *** connect to 6509E MSFC *** &lt;/P&gt;&lt;P&gt;ip add 192.168.90.1 255.255.255.224 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6509E - (L3 SVI) &lt;/P&gt;&lt;P&gt;int vlan 91 &lt;/P&gt;&lt;P&gt;des *** MSFC connect to ASA Inside *** &lt;/P&gt;&lt;P&gt;ip add 192.168.90.5 255.255.255.224 &lt;/P&gt;&lt;P&gt;==== &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6509E MSFC-&amp;gt; connect to FWSM int vlan 95. &lt;/P&gt;&lt;P&gt;==== &lt;/P&gt;&lt;P&gt;6509E MSFC &lt;/P&gt;&lt;P&gt;(NO L2 VALN created in the MSFC only SVI)&lt;/P&gt;&lt;P&gt;int vlan 95 &lt;/P&gt;&lt;P&gt;des *** routing Vlan to FWSM *** &lt;/P&gt;&lt;P&gt;ip add 192.168.95.5 255.255.255.224 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM interface Outisde &lt;/P&gt;&lt;P&gt;int vlan 95 &lt;/P&gt;&lt;P&gt;nameif outside &lt;/P&gt;&lt;P&gt;des *** Routing to 6509E MSFC *** &lt;/P&gt;&lt;P&gt;ip add 192.168.95.1 255.255.255.224 &lt;/P&gt;&lt;P&gt;==== &lt;/P&gt;&lt;P&gt;FWSM interface insde- &lt;/P&gt;&lt;P&gt;(Int Vlan 101 Inside to connect Servers) &lt;/P&gt;&lt;P&gt;int vlan 101 &lt;/P&gt;&lt;P&gt;nameif inside &lt;/P&gt;&lt;P&gt;des *** Connect to Inside Servers *** &lt;/P&gt;&lt;P&gt;ip add 192.168.101.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;===== &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it correct??? If no L2 for the vlan 95 on the MSFC how will it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need your kind input please&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 12:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088832#M79658</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2008-11-01T12:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088833#M79659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All vlans must exist at layer 2 on the 6500 switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For vlan 95 you need &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) For the vlan to exist at L2 ie. a "sh vlan" would show vlan 95&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) A L3 SVI on the MSFC for vlan 95&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For vlan 101 you need the vlan to exist at L2 ONLY on the 6500 switch. No L3 SVI should be created on the MSFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also have you allocated the vlans to the FWSM with the "firewall vlan-group .." command on the 6500 switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 12:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088833#M79659</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-01T12:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088834#M79660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks OK - so you need to assign the VLAN's to the FWSM and it should be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 13:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088834#M79660</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-11-01T13:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088835#M79661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you allocated thos vlan on MSFC for Firewall module and also on context in FWSM ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chintan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 13:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088835#M79661</guid>
      <dc:creator>chintan-shah</dc:creator>
      <dc:date>2008-11-01T13:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088836#M79662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am attaching the configuration of the Switch and the FWSM. Thanks Jon, now my vlan 95 is showing up on the FWSM. But still my inside interface vlan 101 is showing down. i have added one port to the inside vlan 101. but still its showing down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the third file i have mentioned about the configuration i prepared for the switch can any one please validate that also?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088836#M79662</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2008-11-01T16:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088837#M79663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jacob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't get any of attached configuration.&lt;/P&gt;&lt;P&gt;Do you mind to send me config at &lt;A href="mailto:chintan2004@gmail.com"&gt;chintan2004@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088837#M79663</guid>
      <dc:creator>chintan-shah</dc:creator>
      <dc:date>2008-11-01T16:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088838#M79664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, attaching the file again chintan. i will send it through mail also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088838#M79664</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2008-11-01T16:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088839#M79665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your 6500 switch is running in VTP transparent mode but it shows no sign of vlan 95 or vlan 101. The only vlans it shows are vlans 90 &amp;amp; 100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the 6500 switch if you do &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500# sh vlan &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you see entries for vlans 95 &amp;amp; 101. If not you need to create them ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500(config)# vlan 95&lt;/P&gt;&lt;P&gt;6500(config-vlan)# name FWSM_outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500(config)# vlan 101&lt;/P&gt;&lt;P&gt;6500(config-vlan)# name FWSM_inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088839#M79665</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-01T16:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088840#M79666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jacob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see vlna 101 (inside vlan)in layer 2 VLAN database ? Do "show vlan" you should have vlan 101. If you don't have , VLAN 101 will be down  unless you have in layer 2 daatabase.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chintan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088840#M79666</guid>
      <dc:creator>chintan-shah</dc:creator>
      <dc:date>2008-11-01T16:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088841#M79667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jacob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon is correct. you have not created VLAN 101 on MSFC L2 VLAN database. you only have vlna 9 and 100. Please create VLAN 101 in global config mode, you should have vlna 101 up/up state :).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 90&lt;/P&gt;&lt;P&gt; name RoutingVlan-to-ASA&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vlan 100&lt;/P&gt;&lt;P&gt; name Management_Access_Vlan&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088841#M79667</guid>
      <dc:creator>chintan-shah</dc:creator>
      <dc:date>2008-11-01T16:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088842#M79668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sorry, by mistake i attached the previouse file. I am attaching the latest config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i missed to create the inside L2 vlan on the msfc (101) just now i created that and the inside vlan also showing up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But... again i am not able to ping the vlan interface 192.168.101.1 from the msfc also not able to ping the inside hopst 192.168.101.10 to the gateway 192.168.101.1 any thing .. missing??&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088842#M79668</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2008-11-01T16:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088843#M79669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chintan, sorry i updated the file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088843#M79669</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2008-11-01T16:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088844#M79670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"am not able to ping the vlan interface 192.168.101.1 from the msfc"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add this to your config &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM-Pri(config)# management-access inside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"also not able to ping the inside hopst 192.168.101.10 to the gateway 192.168.101.1 any thing"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you mean you can't ping the host from the gateway or the gateway from the host. Have you assigned the switch port that the host is connected to into vlan 101 ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 17:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088844#M79670</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-01T17:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088845#M79671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Jacob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By nature , FWSM doens't allow to ping inside interface from MSFC(outside). &lt;/P&gt;&lt;P&gt;Are you able to ping outside interface of FWSM from MSFC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try folloiwng configuration on FWSM :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit &lt;INSIDEIFNAME&gt;&lt;/INSIDEIFNAME&gt;&lt;/P&gt;&lt;P&gt;icmp permit &lt;OUTSIDEIFNAME&gt;&lt;/OUTSIDEIFNAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try pingging inside interface (GW) from host .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chintan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 17:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088845#M79671</guid>
      <dc:creator>chintan-shah</dc:creator>
      <dc:date>2008-11-01T17:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088846#M79672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we have to add any route in the 6509 Switch for 192.168.101.x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT - in fwsm i just did the NAT for (inside) only, do we need the same for outside also?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM i have added a default route only, it is Connected interface so think no need to add any route for 101.x there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added one port, Gig 1/2, to 101 vlan. and from the host &lt;/P&gt;&lt;P&gt;IP 192.168.101.10 /24 &lt;/P&gt;&lt;P&gt;GW 192.168.101.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not able to ping the gateway from the Host. Also I am not able to ping from the msfc to the outside interface (192.168.95.1 to 192.168.95.5) and reverse also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 18:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088846#M79672</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2008-11-01T18:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088847#M79673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the pinging of the interfaces see Chintan's response ie. you need to allow icmp to the FWSM interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to add a route to the FWSM for the vlan on the inside ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 192.168.101.0 255.255.255.0 &lt;IP address="" of="" fwsm="" outside="" interface=""&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also bear in mind with the FWSM traffic is not allowed through from inside to outside by default. You need to allow it with an acl. This is contrary to the behaviour of standalone pix/asa firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what you mean by NAT. if you want o connect to the inside host from outside then you will need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.101.10 192.168.101.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 18:14:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088847#M79673</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-01T18:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088848#M79674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Chintan / Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thaks a lot, after adding the icmp permit now the host is able to ping the GW and msfc to fwsm outside interface also. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon about NAT, do we need to add NAT statement in FWSM as like we do in the traditional Pix. i dont need any NATing here, i mean to ask do we need to add this statement?&lt;/P&gt;&lt;P&gt;nat (inside) 0 x x&lt;/P&gt;&lt;P&gt;nat (outside) 0 x x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 18:47:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088848#M79674</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2008-11-01T18:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: 6509E Switch Vlan Issue</title>
      <link>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088849#M79675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT works pretty much the same way it does on traditional Pix. Yes you can use &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 192.168.101.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which tells the FWSM not to NAT. You would only need a static if you wanted to initiate the connection from the outside to the 192.168.101.10 host - see previous post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad you got it working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Nov 2008 18:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/6509e-switch-vlan-issue/m-p/1088849#M79675</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-01T18:50:55Z</dc:date>
    </item>
  </channel>
</rss>

