<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't ping FWSM with Basic Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193161#M859577</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We just installed our new FWSM and attempted to upgrade ASDM.  From the 6500, we can session into the FWSM but we &lt;B&gt;CAN'T&lt;/B&gt; ping to it.  Can anyone point out our configuration mistakes? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500 running 12.2(33)SXH4:&lt;/P&gt;&lt;P&gt;&amp;lt;font face="courier"&amp;gt;&lt;/P&gt;&lt;P&gt;interface vlan 400&lt;/P&gt;&lt;P&gt; ip address 10.4.4.3 255.255.255.248&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;&amp;lt;/font&amp;gt;&lt;/P&gt;&lt;P&gt;FWSM:  &lt;/P&gt;&lt;P&gt;&amp;lt;font face="courier"&amp;gt;&lt;/P&gt;&lt;P&gt;hostname FWSM&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan400&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.4.4.1 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list inside extended permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;access-group inside out interface inside&lt;/P&gt;&lt;P&gt;route inside 0.0.0.0 0.0.0.0 10.4.4.3 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 1:00:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512 &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect smtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:7c5bd4abd770cb0bb0014b584ec0c913&lt;/P&gt;&lt;P&gt;&amp;lt;/font&amp;gt;&lt;/P&gt;&lt;P&gt;Thanks. &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:38:25 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2019-03-11T15:38:25Z</dc:date>
    <item>
      <title>Can't ping FWSM with Basic Configuration</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193161#M859577</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We just installed our new FWSM and attempted to upgrade ASDM.  From the 6500, we can session into the FWSM but we &lt;B&gt;CAN'T&lt;/B&gt; ping to it.  Can anyone point out our configuration mistakes? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500 running 12.2(33)SXH4:&lt;/P&gt;&lt;P&gt;&amp;lt;font face="courier"&amp;gt;&lt;/P&gt;&lt;P&gt;interface vlan 400&lt;/P&gt;&lt;P&gt; ip address 10.4.4.3 255.255.255.248&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;&amp;lt;/font&amp;gt;&lt;/P&gt;&lt;P&gt;FWSM:  &lt;/P&gt;&lt;P&gt;&amp;lt;font face="courier"&amp;gt;&lt;/P&gt;&lt;P&gt;hostname FWSM&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan400&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.4.4.1 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list inside extended permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;access-group inside out interface inside&lt;/P&gt;&lt;P&gt;route inside 0.0.0.0 0.0.0.0 10.4.4.3 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 1:00:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512 &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect smtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:7c5bd4abd770cb0bb0014b584ec0c913&lt;/P&gt;&lt;P&gt;&amp;lt;/font&amp;gt;&lt;/P&gt;&lt;P&gt;Thanks. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193161#M859577</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2019-03-11T15:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping FWSM with Basic Configuration</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193162#M859580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you need the "icmp permit any inside". You also need to make sure you are passing the vlans to the FWSM from the switch. You can do this with the command "firewall vlan-group 1 vlan 400" and "firewall module &lt;MODULE&gt; group 1".&lt;/MODULE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 04:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193162#M859580</guid>
      <dc:creator>plumbis</dc:creator>
      <dc:date>2009-06-02T04:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping FWSM with Basic Configuration</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193163#M859586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pete, &lt;/P&gt;&lt;P&gt;Thanks for the quick response.  I forgot to include the following lines in my initial post:  &lt;/P&gt;&lt;P&gt;&lt;FONT face="courier"&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;firewall module 9 vlan-group 1,&lt;/P&gt;&lt;P&gt;firewall vlan-group 1  400&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 04:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193163#M859586</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2009-06-02T04:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can't ping FWSM with Basic Configuration</title>
      <link>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193164#M859598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Pete.  Problem rectified.  +5 from me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 04:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-ping-fwsm-with-basic-configuration/m-p/1193164#M859598</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2009-06-02T04:52:46Z</dc:date>
    </item>
  </channel>
</rss>

