<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM context in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-context/m-p/1342942#M824179</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:faizm@sejeltech.com"&gt;faizm@sejeltech.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;Hi NetGurus,&lt;/P&gt;&lt;P&gt;I have configured 2 contexes called backend and frontend. I have given a default route on both the contexes to reach the SVI on the 6509 switch. I am only able to reach&lt;/P&gt;&lt;P&gt;the SVI IP from the both context and vice versa. But i am unable to ping any other VLAN's created on both the contexts from the MSFC (the SVI). I have configured only&lt;/P&gt;&lt;P&gt;one SVI on the switch and used that as outside VLAN on both the contexts. I have also enabled ICMP permit command as well. What am i missing. Thanks in advance for all.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MFM &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MFM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of things&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) when you say you cannot ping any other vlans - do you mean the vlan interface on the FWSM or hosts on that vlan protected by the FWSM. If you mean the interface then you can't because this is a security feature of the FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If you mean hosts then you need to check 2 things&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i) have you allowed the traffic through with an acl. Be aware that with the FWSM you do not just need an acl for lower to higher security interface (which is standard for all Cisco firewalls) but you also need an acl for higher to lower as well. Alternatively you can enable ICMP inspection on the FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ii) Do you have routes on the MSFC telling it how to get to the vlans protected by the FWSM ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 21 Nov 2009 11:41:00 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-11-21T11:41:00Z</dc:date>
    <item>
      <title>FWSM context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-context/m-p/1342941#M824161</link>
      <description>&lt;P style="text-align: left;"&gt;Hi NetGurus,&lt;/P&gt;&lt;P&gt;I have configured 2 contexes called backend and frontend. I have given a default route on both the contexes to reach the SVI on the 6509 switch. I am only able to reach&lt;/P&gt;&lt;P&gt;the SVI IP from the both context and vice versa. But i am unable to ping any other VLAN's created on both the contexts from the MSFC (the SVI). I have configured only&lt;/P&gt;&lt;P&gt;one SVI on the switch and used that as outside VLAN on both the contexts. I have also enabled ICMP permit command as well. What am i missing. Thanks in advance for all.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MFM &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-context/m-p/1342941#M824161</guid>
      <dc:creator>Mohammed Faiz Mohiuddin</dc:creator>
      <dc:date>2019-03-11T16:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-context/m-p/1342942#M824179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:faizm@sejeltech.com"&gt;faizm@sejeltech.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;Hi NetGurus,&lt;/P&gt;&lt;P&gt;I have configured 2 contexes called backend and frontend. I have given a default route on both the contexes to reach the SVI on the 6509 switch. I am only able to reach&lt;/P&gt;&lt;P&gt;the SVI IP from the both context and vice versa. But i am unable to ping any other VLAN's created on both the contexts from the MSFC (the SVI). I have configured only&lt;/P&gt;&lt;P&gt;one SVI on the switch and used that as outside VLAN on both the contexts. I have also enabled ICMP permit command as well. What am i missing. Thanks in advance for all.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MFM &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MFM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of things&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) when you say you cannot ping any other vlans - do you mean the vlan interface on the FWSM or hosts on that vlan protected by the FWSM. If you mean the interface then you can't because this is a security feature of the FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If you mean hosts then you need to check 2 things&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i) have you allowed the traffic through with an acl. Be aware that with the FWSM you do not just need an acl for lower to higher security interface (which is standard for all Cisco firewalls) but you also need an acl for higher to lower as well. Alternatively you can enable ICMP inspection on the FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ii) Do you have routes on the MSFC telling it how to get to the vlans protected by the FWSM ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Nov 2009 11:41:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-context/m-p/1342942#M824179</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-11-21T11:41:00Z</dc:date>
    </item>
  </channel>
</rss>

