<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange Firewall Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129421#M915151</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest you to restart the firewall once. 90% problem will get resolved. Did you check whats the output of "show cpu usage", you can check the hit count of both the ACLs for icmp permit any any...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls restart and let me know..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Rajesh P&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Aug 2008 09:59:02 GMT</pubDate>
    <dc:creator>secureIT</dc:creator>
    <dc:date>2008-08-06T09:59:02Z</dc:date>
    <item>
      <title>Strange Firewall Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129420#M915147</link>
      <description>&lt;P&gt;I have pix firewall 525 with IOS Version 8.0(3)&lt;/P&gt;&lt;P&gt;I have access-list applied both on inside and outside interface. Everything was working fine but today i m not able to ping firewall outside interface. only directly connected switches are able to ping firewall outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall is configured for AAA server and authentication is working fine but firewall is not able to ping the AAA server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASDM and everything is working, only ping to the box is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have even allowed icmp any any on inside and outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall is unable to reach the SNMP server. Server giving error unreachable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the attachement for configuration of firewall, plus logging at the end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASDM showing that the inside to outside traffic is denied by deny rule, though there is no deny rule even at the end of the access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why it is happening, Please help me out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129420#M915147</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2019-03-11T13:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Firewall Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129421#M915151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest you to restart the firewall once. 90% problem will get resolved. Did you check whats the output of "show cpu usage", you can check the hit count of both the ACLs for icmp permit any any...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls restart and let me know..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Rajesh P&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 09:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129421#M915151</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2008-08-06T09:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Firewall Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129422#M915153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do this,&lt;/P&gt;&lt;P&gt; "clear arp" &lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;"clear conn"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 10:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129422#M915153</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2008-08-06T10:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Firewall Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129423#M915157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi   ..  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in regards to "pings"  to the firewall's interfaces You need to add &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit any inside &lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ICMP entries you have included on the access-list allows pings traversing the firewall and not terminating on its interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps   ..  please rate helpful posts &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 10:17:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129423#M915157</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2008-08-06T10:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Firewall Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129424#M915163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DRDC-Srv-525-1(config)# sh cpu usage &lt;/P&gt;&lt;P&gt;CPU utilization for 5 seconds = 6%; 1 minute: 2%; 5 minutes: 1%&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp hitcount is increasing whenever i try to ping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i m also getting this error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DRDC-Srv-525-1(config)# %PIX-3-315004: Fail to establish SSH session because RSA host key retrieval failed.&lt;/P&gt;&lt;P&gt;%PIX-3-315004: Fail to establish SSH session because RSA host key retrieval failed.&lt;/P&gt;&lt;P&gt;%PIX-3-315004: Fail to establish SSH session because RSA host key retrieval failed.&lt;/P&gt;&lt;P&gt;%PIX-3-315004: Fail to establish SSH session because RSA host key retrieval failed.&lt;/P&gt;&lt;P&gt;%PIX-3-315004: Fail to establish SSH session because RSA host key retrieval failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have restart the firewall now only console is working, unable to access the device via telnet or ssh.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 11:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129424#M915163</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-08-06T11:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Firewall Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129425#M915170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%PIX-3-106014: Deny inbound icmp src inside:172.28.36.4 dst inside:172.28.92.254 (type 8, code 0)&lt;/P&gt;&lt;P&gt;%PIX-3-106014: Deny inbound icmp src inside:172.28.36.4 dst inside:172.28.92.254 (type 8, code 0)&lt;/P&gt;&lt;P&gt;%PIX-3-106014: Deny inbound icmp src inside:172.28.36.4 dst inside:172.28.92.254 (type 8, code 0)&lt;/P&gt;&lt;P&gt;%PIX-3-106014: Deny inbound icmp src inside:172.28.36.4 dst inside:172.28.92.254 (type 8, code 0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fix:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%PIX-4-106023: Deny tcp src outside:172.28.92.226/2088 dst inside:172.28.36.32/23 by access-group "outside_acl" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;%PIX-4-106023: Deny tcp src outside:172.28.92.226/2088 dst inside:172.28.36.32/23 by access-group "outside_acl" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;%PIX-4-106023: Deny tcp src outside:172.28.92.226/2088 dst inside:172.28.36.32/23 by access-group "outside_acl" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fix:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service DRDC_server_ports tcp-udp&lt;/P&gt;&lt;P&gt; port-object eq 23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check your subnet masks on the firewall interface, ACL, object-group and route statements, it seems you have misconfigured some of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aur bhai, Internet par configs post karnay sai pehlay passwords tou delete kardiya kurrou, khuda kai waastay &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 13:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129425#M915170</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-06T13:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Firewall Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129426#M915173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why dont you delete the ssh configuration &amp;amp; RSA keys and reconfigure... your loggs say fail to estabilsh ssh session because RSA host key retrieval failed..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Rajesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 11:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-firewall-issue/m-p/1129426#M915173</guid>
      <dc:creator>secureIT</dc:creator>
      <dc:date>2008-08-07T11:11:18Z</dc:date>
    </item>
  </channel>
</rss>

