05-21-2009 02:10 PM - edited 03-11-2019 08:35 AM
I have a FWSM running 3.1.4 that has an outside and inside interface. There is a server 146.22.x.x on the outside that needs to ftp to 146.27.y.y The FW buffer log shows access-list outside is denying the traffic. I look at access-list outside and the very first line allows 146.22.x.x to 146.27.y.y I add an ACE on top to allow any tcp from 146.22.x.x to 146.27.y.y but still gets the denies in the log. I pipe the hex number on the deny info and it shows that the ACL denying the traffic is my explicit deny ip any any on line 91 of access-list outside. I am using the default class-map and policy-map. FTP is being inspected under the default map. Nat control is turned off on this FWSM. Any suggestions on how to troubleshoot this issue? Thanks
Rommel
Solved! Go to Solution.
05-24-2009 04:38 PM
Without seeing the logs, I can only hazard a guess.
What are the ports of the denied traffic?
05-24-2009 04:38 PM
Without seeing the logs, I can only hazard a guess.
What are the ports of the denied traffic?
08-12-2009 09:38 AM
Update: Received help from TAC and turns out to be an issue with 3.1(4) code. Upgraded to 4.0.4 code as TAC recommended which resolved the issue.
Rommel
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide