<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BandNew PIX 515E issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541967#M527901</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi M8,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your firewall has an FO license, you need to make this unit active to be able to see it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this command, the unit turns into the "Active" state from a failover perspective. It will work after that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;Salem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Feb 2006 14:31:47 GMT</pubDate>
    <dc:creator>scheikhnajib</dc:creator>
    <dc:date>2006-02-07T14:31:47Z</dc:date>
    <item>
      <title>BandNew PIX 515E issue</title>
      <link>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541963#M527897</link>
      <description>&lt;P&gt;I've received a few new PIX 515E security applicances and I'm have layer 2 issues on all that I've tested.  I installed a small 5 port switch on the inside and cannot ping anything from the console.  I have a computer on the switch and it's able to ping other devices on the switch but not the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I find odd is that when I try to ping the inside interface on the PIX from one of the inside computers, the PIX shows the MAC address of the inside computer in the arp table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is to upgrade the PIXs to ver7.0 but I can't do that until I can resolve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is some of the info from one of the PIXs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#sh ver&lt;/P&gt;&lt;P&gt;Cisco PIX Firewall Version 6.3(4)&lt;/P&gt;&lt;P&gt;Cisco PIX Device Manager Version 3.0(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Fri 02-Jul-04 00:07 by morlee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pixfirewall up 29 mins 33 secs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   PIX-515E, 128 MB RAM, CPU Pentium II 433 MHz&lt;/P&gt;&lt;P&gt;Flash E28F128J3 @ 0x300, 16MB&lt;/P&gt;&lt;P&gt;BIOS Flash AM29F400B @ 0xfffd8000, 32KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : VAC+ (Crypto5823 revision 0x1)&lt;/P&gt;&lt;P&gt;0: ethernet0: address is 0015.625a.f7da, irq 10&lt;/P&gt;&lt;P&gt;1: ethernet1: address is 0015.625a.f7db, irq 11&lt;/P&gt;&lt;P&gt;2: ethernet2: address is 000d.8810.902c, irq 11&lt;/P&gt;&lt;P&gt;3: ethernet3: address is 000d.8810.902d, irq 10&lt;/P&gt;&lt;P&gt;4: ethernet4: address is 000d.8810.902e, irq 9&lt;/P&gt;&lt;P&gt;5: ethernet5: address is 000d.8810.902f, irq 5&lt;/P&gt;&lt;P&gt;Licensed Features:&lt;/P&gt;&lt;P&gt;Failover:                    Enabled&lt;/P&gt;&lt;P&gt;VPN-DES:                     Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES:                Disabled&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces: 6&lt;/P&gt;&lt;P&gt;Maximum Interfaces:          10&lt;/P&gt;&lt;P&gt;Cut-through Proxy:           Enabled&lt;/P&gt;&lt;P&gt;Guards:                      Enabled&lt;/P&gt;&lt;P&gt;URL-filtering:               Enabled&lt;/P&gt;&lt;P&gt;Inside Hosts:                Unlimited&lt;/P&gt;&lt;P&gt;Throughput:                  Unlimited&lt;/P&gt;&lt;P&gt;IKE peers:                   Unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This PIX has a Failover Only (FO) license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#sh run&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;hostname pixfirewall&lt;/P&gt;&lt;P&gt;domain-name testlan&lt;/P&gt;&lt;P&gt;access-list acl_out permit icmp any any&lt;/P&gt;&lt;P&gt;no ip address outside&lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.222 255.255.255.0&lt;/P&gt;&lt;P&gt;no failover ip address outside&lt;/P&gt;&lt;P&gt;no failover ip address inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#sh int e1&lt;/P&gt;&lt;P&gt;interface ethernet1 "inside" is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82559 ethernet, address is 0015.625a.f7db&lt;/P&gt;&lt;P&gt;  IP address 192.168.1.222, subnet mask 255.255.255.0&lt;/P&gt;&lt;P&gt;  MTU 1500 bytes, BW 100000 Kbit full duplex&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541963#M527897</guid>
      <dc:creator>cboren</dc:creator>
      <dc:date>2020-02-21T08:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: BandNew PIX 515E issue</title>
      <link>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541964#M527898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You`ll have to allow it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit 192.168.1.0 255.255.255.0 echo inside&lt;/P&gt;&lt;P&gt;icmp permit 192.168.1.0 255.255.255.0 echo-reply inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be careful with you acl_out:&lt;/P&gt;&lt;P&gt;1) would recommend to rename it to inside_in&lt;/P&gt;&lt;P&gt;2) used access-group on IF inside ?&lt;/P&gt;&lt;P&gt;3) be sure to allow more traffic in your acl_out than icmp cause everything else will be automatically denied (implicit deny)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2006 09:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541964#M527898</guid>
      <dc:creator>aduerr</dc:creator>
      <dc:date>2006-02-07T09:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: BandNew PIX 515E issue</title>
      <link>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541965#M527899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I removed my access-list and access-group from the config.  Added the "icmp permit" statements and I still can't ping.  I've tried changing the interface from 10Baset to 100Baset to 100Full.  I can see that the interface is changing by the lights on the switch but none of the devices can ping the firewall.  Also I can't ping anything that I add to the switch.  Yet, all the devices can ping each other and are communicating.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2006 13:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541965#M527899</guid>
      <dc:creator>cboren</dc:creator>
      <dc:date>2006-02-07T13:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: BandNew PIX 515E issue</title>
      <link>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541966#M527900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok lets start with basic, &lt;/P&gt;&lt;P&gt;1 subnets are all the same correct&lt;/P&gt;&lt;P&gt;2 the switch is not mac filtering&lt;/P&gt;&lt;P&gt;3 the switch is all on the same VLAN&lt;/P&gt;&lt;P&gt;4 if you ping from the firewall to machine do you see the mac address in the arp table&lt;/P&gt;&lt;P&gt;5 is the right port with the right access-list and right port on switch.&lt;/P&gt;&lt;P&gt;6 if all else fails set up a capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cap1 permit icmp any any&lt;/P&gt;&lt;P&gt;capture cap1 access-list cap1 interface inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh cap cap1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should be able to ping the gateway on the network that the machie connects to, but to my knowledge not through it to another interface on the pix but i may be wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2006 13:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541966#M527900</guid>
      <dc:creator>kevinhodgson</dc:creator>
      <dc:date>2006-02-07T13:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: BandNew PIX 515E issue</title>
      <link>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541967#M527901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi M8,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your firewall has an FO license, you need to make this unit active to be able to see it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this command, the unit turns into the "Active" state from a failover perspective. It will work after that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;Salem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2006 14:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541967#M527901</guid>
      <dc:creator>scheikhnajib</dc:creator>
      <dc:date>2006-02-07T14:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: BandNew PIX 515E issue</title>
      <link>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541968#M527902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Salem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a bunch.  I thought I had typed that command in the box already.  I tried it again and the PIX is working now.  I can ping out of the PIX and at the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2006 15:01:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bandnew-pix-515e-issue/m-p/541968#M527902</guid>
      <dc:creator>cboren</dc:creator>
      <dc:date>2006-02-07T15:01:10Z</dc:date>
    </item>
  </channel>
</rss>

