<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM context - Admin Down Interface has traffic stats in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-context-admin-down-interface-has-traffic-stats/m-p/1529656#M657809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info. It does sound like that could be the issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Sep 2010 19:09:05 GMT</pubDate>
    <dc:creator>Mel Popple</dc:creator>
    <dc:date>2010-09-29T19:09:05Z</dc:date>
    <item>
      <title>FWSM context - Admin Down Interface has traffic stats</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-context-admin-down-interface-has-traffic-stats/m-p/1529654#M657741</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have noticed that one of my firewall contexts interfaces shows input and output packets even though the interface was in the admin shutdown state during reboot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Vlan111 "DMZ-NET", is administratively down, line protocol is down&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Description: Interface routing to DMZ-NET (Also used for Context Management)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC address 0021.55be.8100, MTU 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address 192.168.4.254, subnet mask 255.255.255.0&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "DMZ-NET":&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 45377 packets input, 3779957 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1130 packets output, 79010 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1999 packets dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The FWSM is running v3.1(7) and is a failover pair (The standby also has traffic stats). Do I have to admin shut the interface in the system context to properly close the interface during boot? Is there something in the way that the FWSM loads its system context configuration first and then loads the individual contexts later that means the interface could be live for a few seconds?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue became apparent after reloading the FWSM during some failover testing prior to deploying it on the network. These switches and FWSMs&amp;nbsp; are cabled to the existing network (with the IPs of the devices they will replace) and it had put a MAC entry in another firewall device which caused an outage. The reason for keeping the interfaces in the admin shutdown state was to avoid anything like this happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mel&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-context-admin-down-interface-has-traffic-stats/m-p/1529654#M657741</guid>
      <dc:creator>Mel Popple</dc:creator>
      <dc:date>2019-03-11T18:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM context - Admin Down Interface has traffic stats</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-context-admin-down-interface-has-traffic-stats/m-p/1529655#M657773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The behavior you saw sounds like a good match for bug CSCta08654. This is fixed in 3.1.15.2 and higher builds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 13:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-context-admin-down-interface-has-traffic-stats/m-p/1529655#M657773</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-09-28T13:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM context - Admin Down Interface has traffic stats</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-context-admin-down-interface-has-traffic-stats/m-p/1529656#M657809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info. It does sound like that could be the issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 19:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-context-admin-down-interface-has-traffic-stats/m-p/1529656#M657809</guid>
      <dc:creator>Mel Popple</dc:creator>
      <dc:date>2010-09-29T19:09:05Z</dc:date>
    </item>
  </channel>
</rss>

