<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem when setting firewall on AS5350XM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745352#M530701</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to configure an extended access list on one AS5350XM but I get one way hearing on a voice calls and I can't determine why (please see the attached diagram). There is an OSPF running on both gigabit interfaces and the Loopback address is also advertised (it is actually the voip IP address). The access list is applied on both interfaces in the inbound direction. There is another gateway with IP:4.4.4.4 (no firewalls here) and the routing between gateways is working properly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is part of the access list (applied on AS5350): &lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;permit ip host 4.4.4.4 host 3.3.3.3&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I review the log of the AS5350xm I see many errors like this one:&lt;/P&gt;&lt;P&gt;%SEC-6-IPACCESSLOGP: list example denied udp 3.3.3.3(16638) -&amp;gt; 4.4.4.4(18094), 1 packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how it is possible to see this error since the access list is in inbound direction and the IP address (4.4.4.4) is open. I don't have problems when I do telnet or ssh from 3.3.3.3 to 4.4.4.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:25:32 GMT</pubDate>
    <dc:creator>mitkin2891</dc:creator>
    <dc:date>2019-03-11T21:25:32Z</dc:date>
    <item>
      <title>Problem when setting firewall on AS5350XM</title>
      <link>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745352#M530701</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to configure an extended access list on one AS5350XM but I get one way hearing on a voice calls and I can't determine why (please see the attached diagram). There is an OSPF running on both gigabit interfaces and the Loopback address is also advertised (it is actually the voip IP address). The access list is applied on both interfaces in the inbound direction. There is another gateway with IP:4.4.4.4 (no firewalls here) and the routing between gateways is working properly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is part of the access list (applied on AS5350): &lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;permit ip host 4.4.4.4 host 3.3.3.3&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I review the log of the AS5350xm I see many errors like this one:&lt;/P&gt;&lt;P&gt;%SEC-6-IPACCESSLOGP: list example denied udp 3.3.3.3(16638) -&amp;gt; 4.4.4.4(18094), 1 packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how it is possible to see this error since the access list is in inbound direction and the IP address (4.4.4.4) is open. I don't have problems when I do telnet or ssh from 3.3.3.3 to 4.4.4.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745352#M530701</guid>
      <dc:creator>mitkin2891</dc:creator>
      <dc:date>2019-03-11T21:25:32Z</dc:date>
    </item>
    <item>
      <title>Problem when setting firewall on AS5350XM</title>
      <link>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745353#M530702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried disabling inspections for voice if any, also have a look at this link :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/customer/tech/tk652/tk698/technologies_tech_note09186a008009484b.shtml"&gt;http://www.cisco.com/en/US/customer/tech/tk652/tk698/technologies_tech_note09186a008009484b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2011 04:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745353#M530702</guid>
      <dc:creator>Parminder Sian</dc:creator>
      <dc:date>2011-09-19T04:20:59Z</dc:date>
    </item>
    <item>
      <title>Problem when setting firewall on AS5350XM</title>
      <link>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745354#M530703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Sian, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply. Everything works ok regarding the voice part. The one way voice issue only appears when I apply the access list in the inbound direction on both interfaces. I see the problem but I don't understand why it happens. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%SEC-6-IPACCESSLOGP: list example denied udp 3.3.3.3(16638) -&amp;gt; 4.4.4.4(18094), 1 packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The loopback interface is with IP 3.3.3.3 and it is not normal to see an inbound packet coming to the router with this source IP (if it is not spoofed of course) expecially going to the 4.4.4.4 which is obviously in the other direction. It looks like that I applied the ACL into the out direction but I didn't. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2011 21:20:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745354#M530703</guid>
      <dc:creator>mitkin2891</dc:creator>
      <dc:date>2011-09-19T21:20:30Z</dc:date>
    </item>
    <item>
      <title>Problem when setting firewall on AS5350XM</title>
      <link>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745355#M530704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any other ideas? I will appreciate any help on this matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 14:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-when-setting-firewall-on-as5350xm/m-p/1745355#M530704</guid>
      <dc:creator>mitkin2891</dc:creator>
      <dc:date>2011-09-22T14:05:39Z</dc:date>
    </item>
  </channel>
</rss>

