<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-problem/m-p/733820#M985086</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To allow ping to the interface try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp perit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The inside interface is given a security level of 100. The outside is given the security level of 0. The lower security level should be pointed toward the least secure network(s). Connections by default are normally permitted from higher to lower security level interfaces. Interface Security levels that are the same are not permitted by default to traverse the firewall even if the policy allows.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jul 2007 22:01:04 GMT</pubDate>
    <dc:creator>JBDanford2002</dc:creator>
    <dc:date>2007-07-05T22:01:04Z</dc:date>
    <item>
      <title>FWSM problem</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-problem/m-p/733819#M985072</link>
      <description>&lt;P&gt;hi all&lt;/P&gt;&lt;P&gt;i am attaching the connectivity diagram.We are using in vlan 1,5,7,11,15 in the 6513 switch.Alos this switch has 2*FWSm modules.Now i am not able to understand how to select the insode and outside interface vlan.I had created a vlan-group 1 and bind that group tp the firewall module 1.All my vlans in the firewall came up.But i am not able to ping them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM:-&lt;/P&gt;&lt;P&gt;int vlan 15&lt;/P&gt;&lt;P&gt;ip add 10.0.4.254 255.255.255.0&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;int vlan 5&lt;/P&gt;&lt;P&gt;ip add 10.0.4.254 255.255.255.0&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;access-list 1 permit icmp any any&lt;/P&gt;&lt;P&gt;access-group 1 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch:-&lt;/P&gt;&lt;P&gt;int vlan 15&lt;/P&gt;&lt;P&gt;ip add 10.0.4.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above configuration is a test configuration.&lt;/P&gt;&lt;P&gt;Please let me know how to select the inside and outside interface.All the connectivity is over MPLS cloud and it is the intra connectivity.Only internet cloud is using for outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-problem/m-p/733819#M985072</guid>
      <dc:creator>shivlu jain</dc:creator>
      <dc:date>2019-03-11T10:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM problem</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-problem/m-p/733820#M985086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To allow ping to the interface try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp perit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The inside interface is given a security level of 100. The outside is given the security level of 0. The lower security level should be pointed toward the least secure network(s). Connections by default are normally permitted from higher to lower security level interfaces. Interface Security levels that are the same are not permitted by default to traverse the firewall even if the policy allows.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2007 22:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-problem/m-p/733820#M985086</guid>
      <dc:creator>JBDanford2002</dc:creator>
      <dc:date>2007-07-05T22:01:04Z</dc:date>
    </item>
  </channel>
</rss>

