<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ICMP echo from Firewall interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/icmp-echo-from-firewall-interface/m-p/1678363#M556773</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi have the follwing scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;two 6509 chassis with VSS configuration.&lt;/P&gt;&lt;P&gt;One of those chassis have one FWSM installed and the configuration is like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Switch&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;firewall multiple-vlan-interfaces&lt;BR /&gt;firewall switch 1 module 3 vlan-group 1&lt;BR /&gt;firewall vlan-group 1&amp;nbsp; 3-5,7,8,10,200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan200&lt;BR /&gt; ip address 10.50.50.1 255.255.255.252&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 172.20.80.0 255.255.255.0 10.50.50.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FSWM&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;interface Vlan10&lt;BR /&gt; nameif ADMIN&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.20.80.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan200&lt;BR /&gt; description Lig. CORE&lt;BR /&gt; nameif FWSM_INSIDE&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.50.50.2 255.255.255.252&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;access-list FWSM_INSIDE extended permit ip any any&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any echo&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any echo-reply&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any unreachable&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any time-exceeded&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any log&lt;BR /&gt;...&lt;/P&gt;&lt;P&gt;icmp permit any ADMIN&lt;BR /&gt;icmp permit any echo ADMIN&lt;BR /&gt;icmp permit any echo-reply ADMIN&lt;BR /&gt;icmp permit any unreachable ADMIN&lt;BR /&gt;icmp permit any time-exceeded ADMIN&lt;BR /&gt;icmp permit any FWSM_INSIDE&lt;BR /&gt;icmp permit any echo FWSM_INSIDE&lt;BR /&gt;icmp permit any echo-reply FWSM_INSIDE&lt;BR /&gt;icmp permit any unreachable FWSM_INSIDE&lt;BR /&gt;icmp permit any time-exceeded FWSM_INSIDE&lt;BR /&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not receiving icmp replays from the fswm interfaces if i try to ping 172.20.80.1 from 10.50.50.2.&lt;/P&gt;&lt;P&gt;I do not see any debuging info in the logs...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I successfully ping 10.50.50.2 from the inside networks int the cat6500, but int the network 172.20.80.0, can not ping 10.50.50.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you help please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;NC&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:27:46 GMT</pubDate>
    <dc:creator>nunoscosta</dc:creator>
    <dc:date>2019-03-11T20:27:46Z</dc:date>
    <item>
      <title>ICMP echo from Firewall interface</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-from-firewall-interface/m-p/1678363#M556773</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi have the follwing scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;two 6509 chassis with VSS configuration.&lt;/P&gt;&lt;P&gt;One of those chassis have one FWSM installed and the configuration is like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Switch&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;firewall multiple-vlan-interfaces&lt;BR /&gt;firewall switch 1 module 3 vlan-group 1&lt;BR /&gt;firewall vlan-group 1&amp;nbsp; 3-5,7,8,10,200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan200&lt;BR /&gt; ip address 10.50.50.1 255.255.255.252&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 172.20.80.0 255.255.255.0 10.50.50.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FSWM&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;interface Vlan10&lt;BR /&gt; nameif ADMIN&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.20.80.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan200&lt;BR /&gt; description Lig. CORE&lt;BR /&gt; nameif FWSM_INSIDE&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.50.50.2 255.255.255.252&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;access-list FWSM_INSIDE extended permit ip any any&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any echo&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any echo-reply&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any unreachable&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any time-exceeded&lt;BR /&gt;access-list FWSM_INSIDE extended permit icmp any any log&lt;BR /&gt;...&lt;/P&gt;&lt;P&gt;icmp permit any ADMIN&lt;BR /&gt;icmp permit any echo ADMIN&lt;BR /&gt;icmp permit any echo-reply ADMIN&lt;BR /&gt;icmp permit any unreachable ADMIN&lt;BR /&gt;icmp permit any time-exceeded ADMIN&lt;BR /&gt;icmp permit any FWSM_INSIDE&lt;BR /&gt;icmp permit any echo FWSM_INSIDE&lt;BR /&gt;icmp permit any echo-reply FWSM_INSIDE&lt;BR /&gt;icmp permit any unreachable FWSM_INSIDE&lt;BR /&gt;icmp permit any time-exceeded FWSM_INSIDE&lt;BR /&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not receiving icmp replays from the fswm interfaces if i try to ping 172.20.80.1 from 10.50.50.2.&lt;/P&gt;&lt;P&gt;I do not see any debuging info in the logs...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I successfully ping 10.50.50.2 from the inside networks int the cat6500, but int the network 172.20.80.0, can not ping 10.50.50.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you help please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;NC&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-from-firewall-interface/m-p/1678363#M556773</guid>
      <dc:creator>nunoscosta</dc:creator>
      <dc:date>2019-03-11T20:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP echo from Firewall interface</title>
      <link>https://community.cisco.com/t5/network-security/icmp-echo-from-firewall-interface/m-p/1678364#M556774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can only ping the local FWSM interface. You cannot ping the other FWSM interfaces like you can on a router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q. I can ping the FWSM interface that is directly connected to my network, but I am unable to ping other interfaces. Is this normal?&lt;BR /&gt;A. Yes. This is a built-in security mechanism that also exists on the PIX Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/partner/products/hw/modules/ps2706/products_qanda_item09186a00801e9e26.shtml#pingissu"&gt;FWSM FAQ&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 May 2011 13:51:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/icmp-echo-from-firewall-interface/m-p/1678364#M556774</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-05-02T13:51:00Z</dc:date>
    </item>
  </channel>
</rss>

