<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM - Ping Working but NO TCP Connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290934#M858272</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please ignore the vlans specified in the previous post, The Original Vlans are Vlan16 (intranet) and Vlan24 (EMS_VLAN), Traffic flow is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC1-&amp;gt;[vlan16-&amp;gt;FWSM-&amp;gt;vlan24]-&amp;gt;PC2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both Vlan 16 and Vlan 24 is created on FWSM. ping is successful from PC1 to PC2. But when you telnet from PC1 to PC2, not gettig, Access list is "permit ip any any" in both the interfaces of Vlan16 and Vlan24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Aug 2009 08:18:32 GMT</pubDate>
    <dc:creator>manuadoor</dc:creator>
    <dc:date>2009-08-12T08:18:32Z</dc:date>
    <item>
      <title>FWSM - Ping Working but NO TCP Connection</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290932#M858268</link>
      <description>&lt;P&gt;I have two interfaces, vlan 45 and vlan 46.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 45 have a security level of 30 and vlan 46 have 25. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a server running on vlan 46, I can ping from the server connected in vlan 45. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have applied "permit ip any any" in both the interfaces in "IN" direction. but when I could not telnet from the server in vlan 45 to vlan 46.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put  a capture in the interface vlan 45, when I ping I can see packets, I cant see any packets when I telnet (or any other TCP). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ultimately I can get any TCP session to vlan 46 from 45.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any inputs are appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290932#M858268</guid>
      <dc:creator>manuadoor</dc:creator>
      <dc:date>2019-03-11T16:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - Ping Working but NO TCP Connection</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290933#M858269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you post your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Aug 2009 03:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290933#M858269</guid>
      <dc:creator>r.poblete</dc:creator>
      <dc:date>2009-08-12T03:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - Ping Working but NO TCP Connection</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290934#M858272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please ignore the vlans specified in the previous post, The Original Vlans are Vlan16 (intranet) and Vlan24 (EMS_VLAN), Traffic flow is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC1-&amp;gt;[vlan16-&amp;gt;FWSM-&amp;gt;vlan24]-&amp;gt;PC2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both Vlan 16 and Vlan 24 is created on FWSM. ping is successful from PC1 to PC2. But when you telnet from PC1 to PC2, not gettig, Access list is "permit ip any any" in both the interfaces of Vlan16 and Vlan24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Aug 2009 08:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290934#M858272</guid>
      <dc:creator>manuadoor</dc:creator>
      <dc:date>2009-08-12T08:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - Ping Working but NO TCP Connection</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290935#M858274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It has been solved as the problem was in the ingress network. Thanks for your help. Hoever it will be great for me if I get ant good docs on FWSM. Already we have another problem of xlate that is not building any connections.. At times when we clear the Xlate, it will start working&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 23:35:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290935#M858274</guid>
      <dc:creator>manuadoor</dc:creator>
      <dc:date>2009-08-13T23:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - Ping Working but NO TCP Connection</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290936#M858276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When addressing any issues with xlates, the best command to consider is 'show xlate detail | inc &lt;IP_ADDRESSS&gt;'.  Try this command for both the source and destination IP address.  Compare the output of this command with the expected interfaces for ingress and egress.  If you are still not sure which xlate is the problem, you can parse through the 'clear xlate ?' command to clear individual xlates.&lt;/IP_ADDRESSS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you determine which xlate is the problem, be sure to investigate all routes, nat/global pairs, and static statements for accuracy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find all FWSM documentation (configuration guides and command references) via the link below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/ps4452/tsd_products_support_model_home.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/ps4452/tsd_products_support_model_home.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 00:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-ping-working-but-no-tcp-connection/m-p/1290936#M858276</guid>
      <dc:creator>Kevin Redmon</dc:creator>
      <dc:date>2009-08-14T00:44:12Z</dc:date>
    </item>
  </channel>
</rss>

