Cisco Catalyst 6500 Series Configuration Manual page 320

Catalyst 6500 series switch and cisco 7600 series router firewall services
Hide thumbs Also See for Catalyst 6500 Series:
Table of Contents

Advertisement

Troubleshooting the Firewall Services Module
To enable ICMP to the FWSM, enter the following command:
Step 2
FWSM/contexta(config)# icmp permit any interface_name
Enter this command for each interface you want to test.
Ping each FWSM interface from the directly connected routers. For transparent mode, ping the
Step 3
management IP address.
This test ensures that the FWSM interfaces are active and that the VLAN configuration is correct.
A ping might fail if the FWSM interface is not active, the VLAN configuration is incorrect, or if a switch
between the FWSM and router is down (see
messages appear on the FWSM, because the packet never reaches it.
Figure 17-2 Ping Failure at FWSM Interface
Router
If the ping reaches the FWSM, and the FWSM responds, you see debug messages like the following:
ICMP echo reply (len 32 id 1 seq 256) 209.165.201.1 > 209.165.201.2
ICMP echo request (len 32 id 1 seq 512) 209.165.201.2 > 209.165.201.1
If the ping reply does not return to the router, then you might have a switch loop or redundant IP
addresses. (See
Figure 17-3 Ping Failure Because of IP Addressing Problems
Router
Step 4
Ping each FWSM interface from a remote host. For transparent mode, ping the management IP address.
This test checks that the directly connected router can route the packet between the host and the FWSM,
and that the FWSM can correctly route the packet back to the host.
A ping might fail if the FWSM does not have a route back to the host through the intermediate router
(see
Figure
message 110001 indicating a routing failure.
Figure 17-4 Ping Failure Because the FWSM has no Route
Host
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
17-6
Ping
Figure
17-3.)
Ping
192.168.1.2
Host
192.168.1.2
17-4). In this case, the debug messages show that the ping was successful, but you see system
Ping
Router
Chapter 17
Monitoring and Troubleshooting the Firewall Services Module
Figure
17-2). In this case, no debug messages or system
FWSM
FWSM
192.168.1.1
?
FWSM
OL-6392-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

7600 series

Table of Contents