<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inconsistent Behavior in FWSM Rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262730#M824163</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there any explicit deny lines in this acl? Pls. grep for all the denies and see if any of which would have denied the flow when this acl was placed in the bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh access-l blah | i deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like PK says when you moved it to the top it worked and continued to work even after you moved it back down until it timed out after which it fails again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logs are your best friend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable logging&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;loggin on&lt;/P&gt;&lt;P&gt;loggin buffered 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh logg | i x.x.x.x where x.x.x.x is the IP address of the host that is getting denied.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Nov 2009 22:36:08 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2009-11-24T22:36:08Z</dc:date>
    <item>
      <title>Inconsistent Behavior in FWSM Rules</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262728#M824093</link>
      <description>&lt;P&gt;We have had two incidents with firewall rules recently.&amp;nbsp; First, we had an access rule that was not working.&amp;nbsp; On a whim, we moved it to the top of the list.&amp;nbsp; It began working.&amp;nbsp; We moved it back down to the bottom of the list.&amp;nbsp; It continued to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today, a rule that had been working stopped working the way intended.&amp;nbsp; There is a rule that allows my workstation to talk to a server on ports 2001 and 2002.&amp;nbsp; Today, the FWSM would allow communication via port 2001 but denied communication via port 2002.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else experienced similar behavior on their FWSM?&amp;nbsp; We are running version 4.0(4).&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262728#M824093</guid>
      <dc:creator>brobson</dc:creator>
      <dc:date>2019-03-11T16:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent Behavior in FWSM Rules</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262729#M824119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are no known similar ACL issue in FWSM 4.0.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe it was that there was a conn established after moving the rule down and it continues to work until the conn timed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check what the logs say for the 2002 port traffic?&lt;/P&gt;&lt;P&gt;These should tell us id the rule is denied by the ACL and on what rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 19:33:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262729#M824119</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-11-24T19:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent Behavior in FWSM Rules</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262730#M824163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there any explicit deny lines in this acl? Pls. grep for all the denies and see if any of which would have denied the flow when this acl was placed in the bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh access-l blah | i deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like PK says when you moved it to the top it worked and continued to work even after you moved it back down until it timed out after which it fails again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logs are your best friend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable logging&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;loggin on&lt;/P&gt;&lt;P&gt;loggin buffered 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh logg | i x.x.x.x where x.x.x.x is the IP address of the host that is getting denied.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 22:36:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262730#M824163</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-11-24T22:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent Behavior in FWSM Rules</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262731#M824187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Re: moving the rule up in the access list.&amp;nbsp; It makes sense that, once the connection was established, it continued to work after we moved it back down in the list.&amp;nbsp; But why did we have to move it up to get it to work in the first place?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Nov 2009 16:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262731#M824187</guid>
      <dc:creator>brobson</dc:creator>
      <dc:date>2009-11-25T16:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent Behavior in FWSM Rules</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262732#M824230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Re: moving the rule up in the access-list.&amp;nbsp; There is only one explicit deny at the end of the list.&amp;nbsp; The new rule was added above the explicit deny.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I'm more concerned about the second issue.&amp;nbsp; We had a rule that was working for over a week when the firewall suddenly starting denying some of the traffic specified by the rule.&amp;nbsp; The rule said, allow any workstation to access server X on ports 2001, 2002 and 2500.&amp;nbsp; On Monday the firewall continued to allow traffic on ports 2001 and 2500 but started explicitely denying traffic on port 2002.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;The rule is in the middle of the access-list.&amp;nbsp; The only deny is at the end of the list.&amp;nbsp; No changes had been made to the access list.&amp;nbsp; The only way I could get it to work was to separate this into three separate rules, one for each port.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Nov 2009 16:54:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262732#M824230</guid>
      <dc:creator>brobson</dc:creator>
      <dc:date>2009-11-25T16:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent Behavior in FWSM Rules</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262733#M824251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That does sound strange.&amp;nbsp; To further address this issue we need to see the output of&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when the flow fails as well as the logs denying the flow indicating acl blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. enable logging and see what it says when the flow breaks.&amp;nbsp; I have not heard of acls going missing after a week of being there and the fact that you have to use 3 lines for each port instead of object group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Nov 2009 17:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-behavior-in-fwsm-rules/m-p/1262733#M824251</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-11-25T17:38:48Z</dc:date>
    </item>
  </channel>
</rss>

