<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM on 6500 TCP connection issues after crash on primary in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-on-6500-tcp-connection-issues-after-crash-on-primary/m-p/2000402#M439326</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;Perhaps, this could be a hardware related issue concerning your Primary FWSM. However, before we can conclude that, could you upgrade your FWSM to the latest image v4.1.7?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Aug 2012 04:38:30 GMT</pubDate>
    <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
    <dc:date>2012-08-17T04:38:30Z</dc:date>
    <item>
      <title>FWSM on 6500 TCP connection issues after crash on primary</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-on-6500-tcp-connection-issues-after-crash-on-primary/m-p/2000401#M439325</link>
      <description>&lt;P&gt;I'm experiencing a rather strange issue that has me stumped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running an FWSM on a 6509 with a SUP720. Firmware 3.2(18), in MultiContext Routed Mode, with shared MSFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything runs fine on this baby most of them time, however occasionally without warning and with no specific pattern the Primary node will fail (as in completely stop responding) and the secondary will takover as active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two get the primary up agian, I reset the hw-module and then no failover active on the secondary to return the primary as active. However, after this event, I start to experience strange issues with connectivity. Certain TCP src dst combinations will just not work. Take the following example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A TCP/1433 connection from Inside IP: 10.3.3.196 to outside IP: 10.252.20.63, logs look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012-08-07 13:43:13:0868&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + 13435&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-07 13:43:09&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Local5.Info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Aug 07 2012 11:31:19: %FWSM-6-302013: Built outbound TCP connection 145674175523995444 for servers:10.3.3.196/64112 (10.3.3.196/64112) to outside:10.252.20.63/1433 (10.252.20.63/1433)&lt;/P&gt;&lt;P&gt;2012-08-07 13:43:13:0868&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + 13436&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-07 13:43:09&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Local5.Info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Aug 07 2012 11:31:19: %FWSM-6-302014: Teardown TCP connection 145674175523995444 for servers:10.3.3.196/64112 to outside:10.252.20.63/1433 duration 0:00:00 bytes 128 TCP Reset-O&lt;/P&gt;&lt;P&gt;2012-08-07 13:43:13:0868&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + 13526&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-07 13:43:09&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Local5.Info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Aug 07 2012 11:31:19: %FWSM-6-106028: Deny TCP (Connection marked for Deletion) from 10.3.3.196/64112 to 10.252.20.63/1433 flags SYN&amp;nbsp; on interface servers&lt;/P&gt;&lt;P&gt;2012-08-07 13:43:13:0875&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + 13670&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-07 13:43:10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Local5.Info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Aug 07 2012 11:31:20: %FWSM-6-302013: Built outbound TCP connection 145674175523995445 for servers:10.3.3.196/64112 (10.3.3.196/64112) to outside:10.252.20.63/1433 (10.252.20.63/1433)&lt;/P&gt;&lt;P&gt;2012-08-07 13:43:13:0875&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + 13671&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-07 13:43:10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Local5.Info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Aug 07 2012 11:31:20: %FWSM-6-302014: Teardown TCP connection 145674175523995445 for servers:10.3.3.196/64112 to outside:10.252.20.63/1433 duration 0:00:00 bytes 124 TCP Reset-O&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However I create a specific ACL on the upstream routers interface, to see if I get any matches and the traffic is not even leaving the 6509. I can however ping the remote device without any issues. And I can confirm that the xlate has been built.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This connection was working fine prior to the crash, and the ACL rules are correct and do allow the connection on both the local FWSM and the remote firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently my only resolution is to&amp;nbsp; reboot the FWSM on both nodes at the same time so that we have a complete fresh start. This is not ideal!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know of issues like this? Any suggestions for workarounds or perhaps ways to troubleshoot the reason for the crash?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-on-6500-tcp-connection-issues-after-crash-on-primary/m-p/2000401#M439325</guid>
      <dc:creator>numchuck</dc:creator>
      <dc:date>2019-03-11T23:39:10Z</dc:date>
    </item>
    <item>
      <title>FWSM on 6500 TCP connection issues after crash on primary</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-on-6500-tcp-connection-issues-after-crash-on-primary/m-p/2000402#M439326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;Perhaps, this could be a hardware related issue concerning your Primary FWSM. However, before we can conclude that, could you upgrade your FWSM to the latest image v4.1.7?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 04:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-on-6500-tcp-connection-issues-after-crash-on-primary/m-p/2000402#M439326</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-17T04:38:30Z</dc:date>
    </item>
  </channel>
</rss>

