<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 4GE SSM - FP L2 rule drop in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780623#M493614</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the delay, weekends and firewalls don't mix &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packet trace output is as follows:&lt;/P&gt;&lt;P&gt;packet-tracer input dmz2 tcp 192.168.4.100 80 212.58.244.68 80&lt;/P&gt;&lt;P&gt;(192.168.4.100 being my test laptop and 212..... being &lt;A href="http://www.bbc.co.uk"&gt;www.bbc.co.uk&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "packet-tracer input dmz2 tcp 192.168.4.100 80 212.58.244.68 80 detailed"&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in&amp;nbsp; id=0xad802ac0, priority=0, domain=permit, deny=true&lt;BR /&gt; hits=5983, user_data=0x0, cs_id=0x0, l3_type=0x0&lt;BR /&gt; src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt; dst mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt; input_ifc=dmz2, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: dmz2&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (l2_acl) FP L2 rule drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Capture to follow....thanks for assisting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Nov 2011 08:54:25 GMT</pubDate>
    <dc:creator>WILLIAM DYEHOUSE</dc:creator>
    <dc:date>2011-11-14T08:54:25Z</dc:date>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780621#M493605</link>
      <description>&lt;P&gt;ASA 5510 running without issues for a while but we needed extra port so added a 4GE SSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having installed the 4GE SSM we had some issues with the card not liking a connection to our switches and only working by plugging directly from the server into the firewall, not great as we wanted extra servers on the line in the future.&amp;nbsp; So we upgraded the firmware and no are at an impasse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have upgraded to 8.0(4)3 and now we cannot get any traffic through the port, we can't even connect to an external DNS server.&amp;nbsp; Running a packet trace I get an immediate error on the first step '(l2_acl) FP L2 rule drop', and it appears as though the outside connection is down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some experience on setting up basic port forwarding and NAT for internet access, webservers, mail but this has thrown me.&amp;nbsp; To be honest its a case of if it aint broke don't fix it so I need some expert help in resolving the problem.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780621#M493605</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2019-03-11T21:49:12Z</dc:date>
    </item>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780622#M493608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you paste your packet tracer output? And also, would you please put a capture of ASP drop send some traffic and then send the output of the show cap? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture asp type asp drop-all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Send some traffic and then do a show cap asp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 18:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780622#M493608</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-11T18:13:06Z</dc:date>
    </item>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780623#M493614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the delay, weekends and firewalls don't mix &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packet trace output is as follows:&lt;/P&gt;&lt;P&gt;packet-tracer input dmz2 tcp 192.168.4.100 80 212.58.244.68 80&lt;/P&gt;&lt;P&gt;(192.168.4.100 being my test laptop and 212..... being &lt;A href="http://www.bbc.co.uk"&gt;www.bbc.co.uk&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "packet-tracer input dmz2 tcp 192.168.4.100 80 212.58.244.68 80 detailed"&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in&amp;nbsp; id=0xad802ac0, priority=0, domain=permit, deny=true&lt;BR /&gt; hits=5983, user_data=0x0, cs_id=0x0, l3_type=0x0&lt;BR /&gt; src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt; dst mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt; input_ifc=dmz2, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: dmz2&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (l2_acl) FP L2 rule drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Capture to follow....thanks for assisting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 08:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780623#M493614</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-14T08:54:25Z</dc:date>
    </item>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780624#M493616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Here is the capture, lots of DNS to Google public servers 8.8.8.8 and 8.8.4.4 which are the settings on the laptop:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 210: 09:23:12.233584 192.168.4.100.58858 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 32 &lt;/P&gt;&lt;P&gt; 215: 09:23:13.220981 192.168.4.100.58858 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 32 &lt;/P&gt;&lt;P&gt; 223: 09:23:14.221012 192.168.4.100.58858 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 32 &lt;/P&gt;&lt;P&gt; 228: 09:23:16.221134 192.168.4.100.58858 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 32 &lt;BR /&gt; 229: 09:23:16.221271 192.168.4.100.58858 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 32 &lt;BR /&gt; 230: 09:23:16.274598 192.168.4.100.55913 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 29 &lt;/P&gt;&lt;P&gt; 232: 09:23:17.268052 192.168.4.100.55913 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 29 &lt;/P&gt;&lt;P&gt; 235: 09:23:17.770513 192.168.4.100.55829 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 29 &lt;BR /&gt; 236: 09:23:18.268022 192.168.4.100.55913 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 29 &lt;/P&gt;&lt;P&gt; 240: 09:23:18.768179 192.168.4.100.55829 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 29 &lt;BR /&gt; 247: 09:23:19.768041 192.168.4.100.55829 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 29 &lt;BR /&gt; 252: 09:23:20.221210 192.168.4.100.58858 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 32 &lt;BR /&gt; 253: 09:23:20.221363 192.168.4.100.58858 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 32 &lt;BR /&gt; 255: 09:23:20.268113 192.168.4.100.55913 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 29 &lt;BR /&gt; 256: 09:23:20.268266 192.168.4.100.55913 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 29 &lt;/P&gt;&lt;P&gt; 259: 09:23:20.910963 192.168.4.100.50101 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 265: 09:23:21.768148 192.168.4.100.55829 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 29 &lt;BR /&gt; 266: 09:23:21.768301 192.168.4.100.55829 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 29 &lt;BR /&gt; 267: 09:23:21.908735 192.168.4.100.50101 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 273: 09:23:22.835146 192.168.4.100.59271 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;BR /&gt; 274: 09:23:22.908827 192.168.4.100.50101 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 276: 09:23:23.830660 192.168.4.100.59271 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;BR /&gt; 277: 09:23:24.268327 192.168.4.100.55913 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 29 &lt;BR /&gt; 278: 09:23:24.268495 192.168.4.100.55913 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 29 &lt;/P&gt;&lt;P&gt; 281: 09:23:24.830721 192.168.4.100.59271 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;BR /&gt; 282: 09:23:24.908796 192.168.4.100.50101 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;BR /&gt; 283: 09:23:24.908888 192.168.4.100.50101 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 287: 09:23:25.768316 192.168.4.100.55829 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 29 &lt;BR /&gt; 288: 09:23:25.768408 192.168.4.100.55829 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 29 &lt;BR /&gt; &lt;BR /&gt; 290: 09:23:26.830782 192.168.4.100.59271 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;BR /&gt; 291: 09:23:26.830920 192.168.4.100.59271 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;BR /&gt; 292: 09:23:27.222980 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 294: 09:23:27.328291 192.168.4.100.56653 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 296: 09:23:27.971339 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 310: 09:23:28.315215 192.168.4.100.56653 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 313: 09:23:28.721382 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;BR /&gt; 314: 09:23:28.908888 192.168.4.100.50101 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;BR /&gt; 315: 09:23:28.908995 192.168.4.100.50101 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 318: 09:23:29.315291 192.168.4.100.56653 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 322: 09:23:30.830889 192.168.4.100.59271 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;BR /&gt; 323: 09:23:30.831026 192.168.4.100.59271 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 325: 09:23:31.269914 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 327: 09:23:31.315337 192.168.4.100.56653 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;BR /&gt; 328: 09:23:31.315489 192.168.4.100.56653 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 330: 09:23:32.018752 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 335: 09:23:32.768438 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;BR /&gt; 336: 09:23:32.770117 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 340: 09:23:33.518482 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 343: 09:23:34.268479 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 348: 09:23:35.315291 192.168.4.100.56653 &amp;gt; 8.8.8.8.53:&amp;nbsp; udp 31 &lt;BR /&gt; 349: 09:23:35.315398 192.168.4.100.56653 &amp;gt; 8.8.4.4.53:&amp;nbsp; udp 31 &lt;/P&gt;&lt;P&gt; 353: 09:23:35.909910 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 357: 09:23:36.659160 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 360: 09:23:37.409204 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 362: 09:23:37.832812 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 364: 09:23:38.581085 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 366: 09:23:39.331129 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 374: 09:23:42.317091 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 376: 09:23:43.065624 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;P&gt; 379: 09:23:43.815631 192.168.4.100.137 &amp;gt; 192.168.4.255.137:&amp;nbsp; udp 50 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 09:36:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780624#M493616</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-14T09:36:38Z</dc:date>
    </item>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780625#M493618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Packet trace for the DNS lookup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "packet-tracer input dmz2 udp 192.168.4.100 53 8.8.8.8 53 detailed"&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in&amp;nbsp; id=0xad802ac0, priority=0, domain=permit, deny=true&lt;BR /&gt; hits=6523, user_data=0x0, cs_id=0x0, l3_type=0x0&lt;BR /&gt; src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt; dst mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt; input_ifc=dmz2, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: dmz2&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (l2_acl) FP L2 rule drop&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 09:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780625#M493618</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-14T09:47:00Z</dc:date>
    </item>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780626#M493620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this might be an ACL configuration issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/s2_711.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa71/command/reference/s2_711.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 11:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780626#M493620</guid>
      <dc:creator>talisman1310</dc:creator>
      <dc:date>2011-11-14T11:12:59Z</dc:date>
    </item>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780627#M493621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The interface is configured as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0&lt;/P&gt;&lt;P&gt;nameif dmz2&lt;/P&gt;&lt;P&gt;security-level 60&lt;/P&gt;&lt;P&gt;ip address 192.168.4.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;ospf cost 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is attempting to get external access (security level 0).&amp;nbsp; Currently there is no ACE/ACL configured on this interface and the ADSM says that there is only the 'implicit rule: Permit all traffic to less secure networks'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT is set as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-192.168.4.0&lt;/P&gt;&lt;P&gt;nat (dmz2,external) dynamic 2XX.1XX.1XX.4X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is configured the same as the other ports already in the ASA this is just a 4GE-SSM port, I have tried all the ports and they are behave the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default is there an implicit deny on SSM ports?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 13:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780627#M493621</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-14T13:21:51Z</dc:date>
    </item>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780628#M493622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any kind of ethertype ACLs? Is the firewall in transparent or Router mode? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 19:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780628#M493622</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-14T19:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780629#M493623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The firewall is in router mode, there are no ACLs on this interface at all.&amp;nbsp; I have setup NAT (dmz2,external) and thats about it.&amp;nbsp; The existing 4 ports are configured in a similar manner worked with just NAT out of the box, the 4 ports on the 4GE-SSM are not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where can I look up ethertype ACLs?&amp;nbsp; Do they appear in the same place as normal ACLs?&amp;nbsp; If they do then I have no I only have the 'implicit: access to less secure' message.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured them as standard ports not using any VLAN functionality.&amp;nbsp; Its a little odd really, do you think I have a duff unit?&amp;nbsp; I can see the traffic light flickering when I attempt a connection and the links go up/down as I disconnect.&amp;nbsp; The only other odd thing I have noticed is when I do a tracer using the ADSM the external link is marked as ? rather than up or down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am struggling here ....HELP! &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 19:58:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780629#M493623</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-14T19:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780630#M493624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you do a show interface and check what is the status of them on the CLI? Also, would you be able to do a show run access-group and see if any ACL is applied? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you move it to an ASA port rather than an SSM one, does it work? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 20:05:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780630#M493624</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-14T20:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780631#M493625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can do anything you like with it in the morning as its driving me nuts!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would a full config help (with the IPs removed and what not)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have moved it to the ASA port and all works fine....its really weird, there isnt a license requirement for the SSM?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 20:09:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780631#M493625</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-14T20:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780632#M493626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope, It may be a faulty SSM module :S &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would definetly Like to see the show module 1 detail and show interfaces to see what is the status of the SSM. Where are you located? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 20:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780632#M493626</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-14T20:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780633#M493627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am in the UK, I can post up any CLI responses tomorrow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show module 1 detail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 20:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780633#M493627</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-14T20:17:10Z</dc:date>
    </item>
    <item>
      <title>4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780634#M493629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup that will be it for now. You can try tomorrow to swap out and then put the module back in... that often helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 20:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780634#M493629</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-14T20:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780635#M493631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK will post back the results tomorrow....Battlefield 3 time now &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 20:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780635#M493631</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-14T20:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780636#M493633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We will track it down, dont worry &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 20:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780636#M493633</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-14T20:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780637#M493634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK here goes, I have powered down the ASA and reseated the card but still no success.&amp;nbsp; Here is the result of 'show interface'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show interface"&lt;/P&gt;&lt;P&gt;Interface Ethernet0/0 "external", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; MAC address 0018.199e.7f58, MTU 1500&lt;BR /&gt; IP address 2XX.1XX.1XX.XXX, subnet mask 255.255.255.240&lt;BR /&gt; 50599 packets input, 43869014 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 40389 packets output, 11509330 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 1 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt; input queue (blocks free curr/low): hardware (255/244)&lt;BR /&gt; output queue (blocks free curr/low): hardware (255/235)&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "external":&lt;BR /&gt; 50599 packets input, 42920030 bytes&lt;BR /&gt; 40389 packets output, 10636033 bytes&lt;BR /&gt; 656 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 78 pkts/sec,&amp;nbsp; 78310 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 59 pkts/sec,&amp;nbsp; 8896 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 68 pkts/sec,&amp;nbsp; 64069 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 55 pkts/sec,&amp;nbsp; 14343 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 1 pkts/sec&lt;BR /&gt;Interface Ethernet0/1 "dmz1", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; MAC address 0018.199e.7f59, MTU 1500&lt;BR /&gt; IP address 192.168.2.1, subnet mask 255.255.255.0&lt;BR /&gt; 10626 packets input, 5136754 bytes, 0 no buffer&lt;BR /&gt; Received 85 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 14826 packets output, 15929354 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 1 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 14 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt; input queue (blocks free curr/low): hardware (255/246)&lt;BR /&gt; output queue (blocks free curr/low): hardware (255/246)&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "dmz1":&lt;BR /&gt; 10612 packets input, 4910710 bytes&lt;BR /&gt; 14826 packets output, 15652088 bytes&lt;BR /&gt; 63 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 1 pkts/sec,&amp;nbsp; 516 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 1 pkts/sec,&amp;nbsp; 494 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 7 pkts/sec,&amp;nbsp; 6167 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 6 pkts/sec,&amp;nbsp; 2384 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 0 pkts/sec&lt;BR /&gt;Interface Ethernet0/2 "internal", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; MAC address 0018.199e.7f5a, MTU 1500&lt;BR /&gt; IP address &lt;INTERNAL ip=""&gt;, subnet mask &lt;INTERNAL subnet="" mask=""&gt;&lt;BR /&gt; 59265 packets input, 23635653 bytes, 0 no buffer&lt;BR /&gt; Received 9823 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 55517 packets output, 44176321 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 1 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 167 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt; input queue (blocks free curr/low): hardware (255/230)&lt;BR /&gt; output queue (blocks free curr/low): hardware (255/230)&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "internal":&lt;BR /&gt; 59098 packets input, 22407185 bytes&lt;BR /&gt; 55517 packets output, 43110583 bytes&lt;BR /&gt; 3447 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 80 pkts/sec,&amp;nbsp; 10312 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 88 pkts/sec,&amp;nbsp; 80758 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 6 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 65 pkts/sec,&amp;nbsp; 11128 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 64 pkts/sec,&amp;nbsp; 62661 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 4 pkts/sec&lt;BR /&gt;Interface Ethernet0/3 "cdmdmz", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; MAC address 0018.199e.7f5b, MTU 1500&lt;BR /&gt; IP address 192.168.3.1, subnet mask 255.255.255.0&lt;BR /&gt; 106 packets input, 18378 bytes, 0 no buffer&lt;BR /&gt; Received 57 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 49 packets output, 17150 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 1 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 11 input reset drops, 0 output reset drops, 0 tx hangs&lt;BR /&gt; input queue (blocks free curr/low): hardware (255/249)&lt;BR /&gt; output queue (blocks free curr/low): hardware (255/251)&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "cdmdmz":&lt;BR /&gt; 95 packets input, 15728 bytes&lt;BR /&gt; 49 packets output, 16178 bytes&lt;BR /&gt; 42 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 0 pkts/sec,&amp;nbsp; 23 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 0 pkts/sec,&amp;nbsp; 18 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 0 pkts/sec&lt;BR /&gt;Interface Management0/0 "management", is down, line protocol is down&lt;BR /&gt;&amp;nbsp; Hardware is i82557, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, Auto-Speed&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; MAC address 0018.199e.7f57, MTU 1500&lt;BR /&gt; IP address 192.168.1.1, subnet mask 255.255.255.0&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 babbles, 0 late collisions, 0 deferred&lt;BR /&gt; 0 lost carrier, 0 no carrier&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;BR /&gt; input queue (curr/max packets): hardware (0/0) software (0/0)&lt;BR /&gt; output queue (curr/max packets): hardware (0/0) software (0/0)&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "management":&lt;BR /&gt; 0 packets input, 0 bytes&lt;BR /&gt; 0 packets output, 0 bytes&lt;BR /&gt; 0 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 0 pkts/sec&lt;BR /&gt; Management-only interface. Blocked 0 through-the-device packets&lt;/INTERNAL&gt;&lt;/INTERNAL&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Interface GigabitEthernet1/0 "dmz2", is up, line protocol is up&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; Hardware is VCS7380 rev01, BW 1000 Mbps, DLY 10 usec&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; Input flow control is unsupported, output flow control is off&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; Media-type configured as RJ45 connector&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; MAC address 0172.10a1.21db, MTU 1500&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; IP address 192.168.4.1, subnet mask 255.255.255.0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 234 packets input, 21658 bytes, 0 no buffer&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; Received 59 broadcasts, 0 runts, 0 giants&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 0 pause input, 0 resume input&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 0 L2 decode drops&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 3 packets output, 192 bytes, 0 underruns&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 0 pause output, 0 resume output&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 0 output errors, 0 collisions, 0 interface resets&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 0 late collisions, 0 deferred&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 0 rate limit drops&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 0 input reset drops, 0 output reset drops&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; input queue (blocks free curr/low): hardware (0/0)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; output queue (blocks free curr/low): hardware (0/0)&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; Traffic Statistics for "dmz2":&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 231 packets input, 17276 bytes&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 3 packets output, 84 bytes&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 229 packets dropped&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 0 pkts/sec,&amp;nbsp; 5 bytes/sec&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 0 pkts/sec,&amp;nbsp; 19 bytes/sec&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 0 pkts/sec&lt;/STRONG&gt;&lt;BR /&gt;Interface GigabitEthernet1/1 "dmz3", is down, line protocol is down&lt;BR /&gt;&amp;nbsp; Hardware is VCS7380 rev01, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; Auto-Duplex, Auto-Speed&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; Media-type configured as RJ45 connector&lt;BR /&gt; MAC address 0172.10a1.21dc, MTU 1500&lt;BR /&gt; IP address 192.168.5.1, subnet mask 255.255.255.0&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;BR /&gt; input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt; output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "dmz3":&lt;BR /&gt; 0 packets input, 0 bytes&lt;BR /&gt; 0 packets output, 0 bytes&lt;BR /&gt; 0 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 0 pkts/sec,&amp;nbsp; 0 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 0 pkts/sec&lt;BR /&gt;Interface GigabitEthernet1/2 "", is administratively down, line protocol is down&lt;BR /&gt;&amp;nbsp; Hardware is VCS7380 rev01, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; Auto-Duplex, Auto-Speed&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; Media-type configured as RJ45 connector&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address 0172.10a1.21dd, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;BR /&gt; input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt; output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;Interface GigabitEthernet1/3 "", is administratively down, line protocol is down&lt;BR /&gt;&amp;nbsp; Hardware is VCS7380 rev01, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; Auto-Duplex, Auto-Speed&lt;BR /&gt; Input flow control is unsupported, output flow control is off&lt;BR /&gt; Media-type configured as RJ45 connector&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address 0172.10a1.21de, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;BR /&gt; input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt; output queue (blocks free curr/low): hardware (0/0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 08:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780637#M493634</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-15T08:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780638#M493635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Show module command says its up!&amp;nbsp; Firmware 1.0 never really fills me with confidence though....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show module 1 detail"&lt;/P&gt;&lt;P&gt;Cisco 4-Port Gigabit Ethernet Module&lt;BR /&gt;Model:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSM-4GE&lt;BR /&gt;Hardware version:&amp;nbsp;&amp;nbsp; 1.0&lt;BR /&gt;Serial Number:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; JAF1327APHP&lt;BR /&gt;Firmware version:&amp;nbsp;&amp;nbsp; 1.0(0)8&lt;BR /&gt;Software version:&amp;nbsp;&amp;nbsp; 1.0(0)10&lt;BR /&gt;MAC Address Range:&amp;nbsp; 0172.10a1.21db to 0172.10a1.21de&lt;BR /&gt;Data plane Status:&amp;nbsp; Up&lt;BR /&gt;Status:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Up&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 08:46:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780638#M493635</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-15T08:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780639#M493636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only ACLs are:&lt;/P&gt;&lt;P&gt;external_access_in for incoming mail/www/usual services.&lt;/P&gt;&lt;P&gt;dmz1_access_in for dmz1 to internal mail traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT for dmz2:&lt;/P&gt;&lt;P&gt;object network obj-192.168.4.0&lt;/P&gt;&lt;P&gt;nat (dmz2,external) dynamic 2XX.1XX.1XX.XX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2XX.1XX.1XX.XX is the external IP used for all browsing from any interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 08:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780639#M493636</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-15T08:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: 4GE SSM - FP L2 rule drop</title>
      <link>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780640#M493637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have setup remote access to the firewall ADSM so if you need more information please reply to this thread and I should be able to post any results of commands and config info.&amp;nbsp; This has me stumped it all looks right &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 14:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4ge-ssm-fp-l2-rule-drop/m-p/1780640#M493637</guid>
      <dc:creator>WILLIAM DYEHOUSE</dc:creator>
      <dc:date>2011-11-15T14:56:48Z</dc:date>
    </item>
  </channel>
</rss>

