<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM Inter-VLAN Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854799#M492050</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to confirm this is an ACL issue.&lt;/P&gt;&lt;P&gt;Can you place a permit ip any any and check the logs please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Nov 2011 23:19:38 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2011-11-30T23:19:38Z</dc:date>
    <item>
      <title>FWSM Inter-VLAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854796#M492047</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've looked through this site on multiple occasions and there has already been topics or questions that helped resolve mine however this one that I'm having doesn't appear to be anywhere. I'm having a problem with our 6500 and our FWSM. The problem I'm having is inter-vlan communication. So, We have our FWSM running multiple contexts for clients, and I have an admin Context in there as well. With this network I would like to be able to access every server from it from very context from it. However I am having some difficulty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, basically I have setup a NAT statement on both sides of the contexts and an access list permitting icmp and ip traffic between the two contexts., however I have no communuication. I notice when I run show access-list that the access-list for the NAT statement builds up after a string of pings so the NAT is definetely happening, however it is getting denied. This is the error that fills up in the logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny tcp src outside1:1.1.1.1/49163 dst inside1:2.2.2.2/80 by access-group "" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny icmp src outside1:1.1.1.1/49163 dst inside1:2.2.2.2/80 by access-group "" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone ever seen this before and maybe could provide some insight. Thank You very much in advance for all who help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the config for the FWSM Context that is giving the denies. The other side doesn't give denies. .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlanx&lt;/P&gt;&lt;P&gt; nameif outside7&lt;/P&gt;&lt;P&gt; bridge-group z&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlany&lt;/P&gt;&lt;P&gt; nameif inside7&lt;/P&gt;&lt;P&gt; bridge-group z&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BVIz&lt;/P&gt;&lt;P&gt; ip address &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSIDE extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit icmp any any echo&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list NO_NAT_INSIDE extended permit ip 1.1.1.1 255.255.255.255 2.2.2.2 255.255.255.255&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu outside1 1500&lt;/P&gt;&lt;P&gt;mtu inside1 1500&lt;/P&gt;&lt;P&gt;icmp permit any outside7&lt;/P&gt;&lt;P&gt;icmp permit any inside7&lt;/P&gt;&lt;P&gt;global (outside7) 1 x.x.x.x&lt;/P&gt;&lt;P&gt;nat (inside7) 0 access-list NO_NAT_INSIDE&lt;/P&gt;&lt;P&gt;nat (inside7) 1 p.p.p.p a.a.a.a&lt;/P&gt;&lt;P&gt;access-group INSIDE in interface inside7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns maximum-length 512&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect smtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854796#M492047</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2019-03-11T21:57:36Z</dc:date>
    </item>
    <item>
      <title>FWSM Inter-VLAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854797#M492048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the following and let me know the result:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list OUTSIDE extended permit icmp any any echo&lt;/P&gt;&lt;P&gt;no access-list OUTSIDE extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt; access-list OUTSIDE permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Nov 2011 23:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854797#M492048</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-11-30T23:01:16Z</dc:date>
    </item>
    <item>
      <title>FWSM Inter-VLAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854798#M492049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick response jcarvaja. I tried exactly what you requested, however the logs still give me the same deny statement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Nov 2011 23:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854798#M492049</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2011-11-30T23:08:13Z</dc:date>
    </item>
    <item>
      <title>FWSM Inter-VLAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854799#M492050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to confirm this is an ACL issue.&lt;/P&gt;&lt;P&gt;Can you place a permit ip any any and check the logs please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Nov 2011 23:19:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854799#M492050</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-11-30T23:19:38Z</dc:date>
    </item>
    <item>
      <title>FWSM Inter-VLAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854800#M492051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jcarvaja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick response again. The issue was I never applied the access group for the outside interfaces. Once this was applied on both sides of the contexts the pings went through successfully. Thanks Again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2011 04:02:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854800#M492051</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2011-12-01T04:02:21Z</dc:date>
    </item>
    <item>
      <title>FWSM Inter-VLAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854801#M492052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Excelent that we now have solved the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a wonderful night!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2011 05:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-inter-vlan-issue/m-p/1854801#M492052</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-01T05:06:24Z</dc:date>
    </item>
  </channel>
</rss>

