<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM, nat exemption issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402046#M750821</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also are there any shared interfaces between the contexts?&lt;/P&gt;&lt;P&gt;If so are you using context classification to ensure that traffic is forwarded to the correct context?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Jan 2010 19:18:20 GMT</pubDate>
    <dc:creator>stuart</dc:creator>
    <dc:date>2010-01-22T19:18:20Z</dc:date>
    <item>
      <title>FWSM, nat exemption issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402039#M750814</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have an FWSM that's using different contexts. We are using nat exemption in some of these contexts, sometimes our users in the outside can't access to the inside. This already happened in different contexts and diferents hosts. And when the problem occur some machines in the same vlan (configured in the FWSM in the same way) had the problem and were working fine. After delete the nat configuration and add it again, all machines started to work fine again. Can this be caused by a bug? Or can we be hitting the translations limit? We are using the version 3.2(2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402039#M750814</guid>
      <dc:creator>Norberto Salgado</dc:creator>
      <dc:date>2019-03-11T16:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM, nat exemption issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402040#M750815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It could be many things.&lt;/P&gt;&lt;P&gt;1. incorrect static&lt;/P&gt;&lt;P&gt;2. proxy arp&lt;/P&gt;&lt;P&gt;3. xlate exhaustion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since this is multiple context I'd suggest opening a TAC case so, they can collect the necessary data at the time of the problem to identify the root cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jan 2010 15:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402040#M750815</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-20T15:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM, nat exemption issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402041#M750816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;P class="MsoPlainText"&gt;Thank you for your reply.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;1.If it's an incorrect static, shouldn't the problem be continuous and always occur in same hosts?&lt;/P&gt;&lt;P class="MsoPlainText"&gt;2.The limit for xlate it's 256k for all contexts correct?&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Can you advise me some troubleshooting document on this?&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Thank you.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Best regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jan 2010 15:40:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402041#M750816</guid>
      <dc:creator>Norberto Salgado</dc:creator>
      <dc:date>2010-01-20T15:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM, nat exemption issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402042#M750817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately there is no troubleshooting document for this probelm as this could be caused by too many issues that I stated about including routing issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;X-late limit is 256K divided between all contexts. You are correct.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/specs_f.html#wp1056716"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/specs_f.html#wp1056716&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before and during the problem you should collect the following:&lt;/P&gt;&lt;P&gt;1. sh xlate debug | i x.x.x.x&lt;/P&gt;&lt;P&gt;2. syslogs (level 7) when the flow breaks&lt;/P&gt;&lt;P&gt;3. sh arp | i x.x.x.x before and during&lt;/P&gt;&lt;P&gt;5. sh xlate count (do it on all contexts to see if one context is using up all the slots)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jan 2010 16:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402042#M750817</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-20T16:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM, nat exemption issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402043#M750818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've asked some logs and the only thing that I see that can be related to problem it's this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%FWSM-4-410001: Dropped UDP DNS request from InsideVLAN:a.a.a.a/20498 to Outside:b.b.b.b/53; label length 108 bytes exceeds protocol limit of 63 bytes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where a.a.a.a it's the IP of one of the servers in wich we were unable to access from the outside at the time that message appears in logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this be related with the issue?&lt;/P&gt;&lt;P&gt;I only got that message in syslog in the time that the problem occur, if this it's the cause of the problem, maybe we should see more of this messages.&lt;/P&gt;&lt;P&gt;But it's a bit coincidence that the only message that we got at the time of the problem it's relative to one of the machines that we were having problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jan 2010 14:21:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402043#M750818</guid>
      <dc:creator>Norberto Salgado</dc:creator>
      <dc:date>2010-01-21T14:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM, nat exemption issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402044#M750819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the output of the show np stats 3 I can see a lot of Close Notify Errors, any idea of what can be causing this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Discard Statistics&lt;BR /&gt;&amp;nbsp; ------------------&lt;BR /&gt;&amp;nbsp; Ingress Discards&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8100 Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Emb Xlate Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Process Ack Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;Close Notify Errors&amp;nbsp;&amp;nbsp;&amp;nbsp; : 123317&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; D300 Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bad Vlan Id Packets&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; VFT Load Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PIF Load Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Xlate Create Errors&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ingress Aborts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; Egress Discards&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 31531514&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Xlate Read Error&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; D300 Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Not Outside Xlate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Out Xlate Create&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console Accs Denied&amp;nbsp;&amp;nbsp;&amp;nbsp; : 62323&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; AAA Denied Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; AAA&amp;nbsp; Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACL Denied Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 26486601&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLV Error Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Shunned Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Too many connections&amp;nbsp;&amp;nbsp; : 207&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rev Route Lkup Fail&amp;nbsp;&amp;nbsp;&amp;nbsp; : 263816&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inbound Deny (!static) : 22476&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Self Route Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 4638527&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session Mgmt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bad Vlan Id Packets&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Read Global Table Fail : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ARP drop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; VFT Load Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Pif Load Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bad IP Length Packets&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Checksum Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Xlate Create Errors&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Est&amp;lt;-&amp;gt;HO Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; HO Insert Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ICMP Msg Orig Pkts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unsupported AAA Config : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sess Mgmt RL Drops&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 21&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Nat0 SSLC Outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Egress Aborts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Management Only Ifc&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Route Misses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 31005&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; VF Disable Drops&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny Conns (Low PC Mem): 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny Conns (Conn State): 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SMTP Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Assert Soft&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GPH Frame&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ICMP Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 33&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Resource Allocate Fail : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Invalide IP Addr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Classify Fail&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Nat Lookup Fail&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 26423&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy CLS Lookup FaiL : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy CLS Permit Fail : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Not Equal CLS&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Nat and Global Conflict: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface Down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 74&lt;BR /&gt; &lt;BR /&gt; Xlate Create Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp; HO Insert Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp; Reset Pkts Generated&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp; VFT Load Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;&amp;nbsp; PIF Load Errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jan 2010 17:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402044#M750819</guid>
      <dc:creator>Norberto Salgado</dc:creator>
      <dc:date>2010-01-21T17:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM, nat exemption issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402045#M750820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like this could be down to your DNS being dropped by the default DNS inspection policy.&lt;/P&gt;&lt;P&gt;Do a show service-policy on the FWSM depending on the code version should look something like the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh service-policy &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global policy: &lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;Inspect: dns preset_dns_map, packet 0, drop 0, reset-drop 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;See if you have any drops in this line. If you users are accessing the servers by name for instance this could explain your outages.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;The default policy should look like the below, if this has been modified to a lesser length could be the cause?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just something to check out, along side the potential NAT issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stu&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 19:12:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402045#M750820</guid>
      <dc:creator>stuart</dc:creator>
      <dc:date>2010-01-22T19:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM, nat exemption issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402046#M750821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also are there any shared interfaces between the contexts?&lt;/P&gt;&lt;P&gt;If so are you using context classification to ensure that traffic is forwarded to the correct context?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 19:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-exemption-issue/m-p/1402046#M750821</guid>
      <dc:creator>stuart</dc:creator>
      <dc:date>2010-01-22T19:18:20Z</dc:date>
    </item>
  </channel>
</rss>

