12-08-2008 04:35 AM - edited 03-11-2019 07:22 AM
Hi,
I am unable to ping from inside vlan100 interface 10.X.x.x to outside vlan 2interface 10.x.x.x in the FWSM.What is the problem and give the idea.
12-08-2008 04:47 AM
It could be quite a few things but the first thing to check is that the FWSM behaves slightly differently than pix or ASA firewalls.
On pix and asa firewalls traffic is allowed by default from a higher to a lower security interface. This is not the case with the FWSM, you need an access-list on the inside interface that allows the traffic.
Jon
12-08-2008 04:52 AM
HI,
access list is also done
12-08-2008 04:57 AM
Where are you pinging from and where are you pinging to ?
Have you configured NAT ?
Jon
12-08-2008 05:02 AM
After giving no nat control command ,its ping
Thanks lot
12-08-2008 05:06 AM
Okay, it would help if you could perhaps give a bit more info than just a quick sentence.
What is the device you are running the ping command on ?
What is the destination device you are pinging to ?
Are both your vlan interfaces on the FWSM in the up/up state ?
Jon
12-08-2008 05:11 AM
What is the device you are running the ping command on ?
4509 switch
What is the destination device you are pinging to ?
7500 series router
Are both your vlan interfaces on the FWSM in the up/up state ?
yes
12-08-2008 05:34 AM
Can you post config of
1) FWSM
2) 6500 switch which includes the "sh firewall vlan-group" command
Is the FWSM in single or multi context.
Is the FWSM in transparent or routed mode.
Jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide