07-27-2008 11:31 AM - edited 03-09-2019 09:10 PM
I have FWSM module installed in 6509e catalyst switch. I have configured 2 vlans as follows.
HR VLAN ID 16--- Gateway----X.X.16.1
Management VLAN ID 18 Gateway---X.X.18.1
i am trying to ping from host in 16 vlan to a host in 18 vlan which is successful but i cant ping 18 vlan gateway which is X.X.18.1. why it is so?
please reply.
Solved! Go to Solution.
08-07-2008 11:30 PM
08-01-2008 11:26 AM
Check the vlan configuration on FWSM module in 6500 as configuration issues may cause the ping to fail.
Refer the following url for more info on assigning the VLANs to FWSM:
http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/configuration/guide/switch.html#wp1175820
08-01-2008 06:01 PM
check the following
1 ACLs in both direction because FWSM not like ASA regardless the security level u have u need to make ACL to permit traffic to flow by default evrything is denied
secondly
eable icmp and icmp error inspection
also make sure u have the right VLANs assigned to the FWSM, ports and client
finally make sure the client has the right default gateway
good luck
please if helpful Rate
08-02-2008 12:17 PM
Ahmad, are you trying to ping from a 'host' in the vlan 16 subnet to the FWSM's Vlan 18 SVI (Gateway interface)?
If so, I'm afraid this will not work. The FWSM/ASA/PIX do not allow pinging any of its interfaces UNLESS you are part of the same interface subnet/zone. For example Vlan 16 users can only ping -X.X.16.1 and NOT -X.X.18.1 and similarly Vlan 18 users can only ping -X.X.18.1.
Regards
Farrukh
08-04-2008 09:42 PM
Gentlemen!
Thanks alot for your replies, i am going to enable icmp error on the fwsm to make sure about the ping.
Farrukh
someone told me that FWSM will not allow to ping from one vlan to the other vlan gateway. in my case,
it is a host in X.X.16.X vlan can ping its own gateway which is X.X.16.1 and can also ping host in X.X.18.X vlan but cant ping X.X.18.1 which is the gateway for vlan 18. What is the logic, y it cant ping.
Thanks
08-04-2008 09:55 PM
As I told you this is one of the 'rules' of FWSM/ASA/PIX. Perhaps they did this to prevent 'mapping' of zones or something, personally I find it very annoying.
You will 'not' be able to ping X.X.18.1 from ANY machine in the X.X.16.X zone. Please check my previous post also, I said the same things.
Regards
Farrukh
08-02-2008 06:58 PM
in addition
if u wanna try to ping any cisco firewall interface from other interface u will not be able
but as long as u ping the clients behind that interface
so u your configurations if fine
and nothing to worry about
good luck
please, rate if helpful
08-07-2008 02:00 PM
Thanks everyone! I think it was quite helpful.
Regards
Sajjad
08-07-2008 04:22 PM
u welcome
please, rate the helpful post
08-07-2008 11:30 PM
OK thats great, please rate if helpful.
Regards
Farrukh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide