cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1074
Views
0
Helpful
6
Replies

FWSM Explicit deny strange behavior

phmazzoni
Level 1
Level 1

Hello,

I am having problems with a FWSM with multiple contexts implementation.

One of the contexts has a inside interface that must have a EXPLICIT deny ip any any.

The problem is:

When I put the ACE with the explicit deny at the end of the ACL all the traffic EXPLICIT permitted before it stops working.

If I remove the explicit deny, letting the IMPLICIT deny work, everything runs fine.

I am running the 4.0(4) code.

Any ideas?

Thanks in advance,

Pedro Mazzoni

6 Replies 6

Panos Kampanakis
Cisco Employee
Cisco Employee

Pedro,

Are you using ACL optimization?

PK

No PK, I am not using ACL optimization.

Thanks,
Pedro

Sorry for the wrong answer PK, but I am using it.
I didn't know that this is enable by default.

No worries.

Let us know if this is answered.

PK

PK, do you think that this might be the problem?

If yes, how can ACL optimization cause it?

Thanks

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtc97643

Fix is in 4.0.9 or above.

Or disable acl optimization.

http://www.cisco.com/cgi-bin/tablebuild.pl/cat6000-fwsm

Click on the All new releases will be available "here"

The latest in the 4.0 train is 4.0.13
ASDM is asdm-62(1)f.bin

-KS

Review Cisco Networking for a $25 gift card