<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: %FWSM-3-305006: portmap translation creation failed for icmp in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364639#M720046</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, as per design, you can't ping the opposite interface of the firewall, whether it is ping from the outside host towards the &lt;SPAN style="text-decoration: underline;"&gt;inside or FWSM interface&lt;/SPAN&gt;, OR/ ping from an inside host towards the &lt;SPAN style="text-decoration: underline;"&gt;outside interface&lt;/SPAN&gt; or &lt;SPAN style="text-decoration: underline;"&gt;FWSM interface&lt;/SPAN&gt; of the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only ping as per the following:&lt;/P&gt;&lt;P&gt;- Ping through the FWSM, ie: from inside host towards outside host, and vice versa. In this case, you would need to configure "inspect icmp".&lt;/P&gt;&lt;P&gt;- Ping the direct FWSM interface, ie: from inside host, you can only ping the inside interface, from the outside host, you can ping the outside interface, etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Mar 2010 06:56:29 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-03-22T06:56:29Z</dc:date>
    <item>
      <title>%FWSM-3-305006: portmap translation creation failed for icmp src outside</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364634#M720041</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured my FWSM with no nat-control, simple routing mode, but i am getting following error log when i ping from host residing at the outside interface of FWSM to inside interface of FWSM, I know that inside interface of FWSM cannot be pingged as per FWSM design, but i need to know why i am getting this error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri; font-size: 10pt;"&gt;&lt;SPAN style="font-family: Calibri; font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;4:11:38 Local4.Error 192.168.49.11 Mar 07 2010 14:09:32: %FWSM-3-305006: portmap translation creation failed for icmp src outside:192.168.255.5 dst inside:192.168.48.225 (type 8, code 0)&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;interface Vlan99&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 192.168.49.11 255.255.255.240 standby 192.168.49.12 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan57&lt;BR /&gt; nameif FWSM&lt;/P&gt;&lt;P dir="ltr"&gt; security-level 85&lt;BR /&gt; ip address 192.168.57.1 255.255.255.0 standby 192.168.57.2 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan6&lt;BR /&gt; nameif inside&lt;/P&gt;&lt;P dir="ltr"&gt; security-level 90&lt;BR /&gt; ip address 192.168.48.225 255.255.255.224 standby 192.168.48.226&lt;/P&gt;&lt;P dir="ltr"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;!&lt;BR /&gt;interface Vlan67&lt;BR /&gt; nameif FWSM_2&lt;BR /&gt; security-level 80&lt;BR /&gt; ip address 192.168.67.1 255.255.255.0 standby 192.168.67.2&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;route outside 0.0.0.0 0.0.0.0 192.168.49.1 1 (towards MSFC)&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging standby&lt;BR /&gt;logging emblem&lt;BR /&gt;logging console debugging&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging history debugging&lt;BR /&gt;logging asdm debugging&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;I would appreciate if some one can share the experince.&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;Regards,&lt;/P&gt;&lt;SPAN style=": ; font-size: 2; font-family: Calibri; "&gt;&lt;P dir="ltr"&gt;Nad&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri; font-size: 2; "&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364634#M720041</guid>
      <dc:creator>Nadeem ahmed Ahmed</dc:creator>
      <dc:date>2019-03-11T17:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: %FWSM-3-305006: portmap translation creation failed for icmp</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364635#M720042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have&lt;/P&gt;&lt;P&gt;static (inside,outside) &lt;SPAN style="font-size: 10pt; font-family: Calibri; "&gt;192.168.48.0 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Calibri; "&gt;192.168.48.0 net 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, pls. enable icmp inspection under the policy-map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Mar 2010 22:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364635#M720042</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-21T22:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: %FWSM-3-305006: portmap translation creation failed for icmp</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364636#M720043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately there is no specific syslog messages for pinging the wrong interface of the fwsm. The syslog message that you are seeing will be the one generated for pinging the wrong interface of the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 04:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364636#M720043</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-22T04:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: %FWSM-3-305006: portmap translation creation failed for icmp</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364637#M720044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have disabled the Nat-control, FWSM is working in pure routing mode..?&lt;/P&gt;&lt;P&gt;Also what will be the use of enabling icmp inspection in my scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 06:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364637#M720044</guid>
      <dc:creator>Nadeem ahmed Ahmed</dc:creator>
      <dc:date>2010-03-22T06:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: %FWSM-3-305006: portmap translation creation failed for icmp</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364638#M720045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A class="jiveTT-hover-user jive-username-link" href="https://community.cisco.com/people/halijenn" id="jive-16889019,821,407,681,342,585" onmouseout="" onmouseover=""&gt;&lt;STRONG style="color: #555555; "&gt;halijenn&lt;/STRONG&gt;&lt;/A&gt; ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting this message only when i ping to inside interface while no syslog message comes with other interfaces... Is it due to the most secure interface ? while other less secure interface are not giving any syslog message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest if any!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rg&lt;/P&gt;&lt;P&gt;nad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 06:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364638#M720045</guid>
      <dc:creator>Nadeem ahmed Ahmed</dc:creator>
      <dc:date>2010-03-22T06:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: %FWSM-3-305006: portmap translation creation failed for icmp</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364639#M720046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, as per design, you can't ping the opposite interface of the firewall, whether it is ping from the outside host towards the &lt;SPAN style="text-decoration: underline;"&gt;inside or FWSM interface&lt;/SPAN&gt;, OR/ ping from an inside host towards the &lt;SPAN style="text-decoration: underline;"&gt;outside interface&lt;/SPAN&gt; or &lt;SPAN style="text-decoration: underline;"&gt;FWSM interface&lt;/SPAN&gt; of the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only ping as per the following:&lt;/P&gt;&lt;P&gt;- Ping through the FWSM, ie: from inside host towards outside host, and vice versa. In this case, you would need to configure "inspect icmp".&lt;/P&gt;&lt;P&gt;- Ping the direct FWSM interface, ie: from inside host, you can only ping the inside interface, from the outside host, you can ping the outside interface, etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 06:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-3-305006-portmap-translation-creation-failed-for-icmp-src/m-p/1364639#M720046</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-22T06:56:29Z</dc:date>
    </item>
  </channel>
</rss>

