Disabling The Test Configuration - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 26
Troubleshooting the Firewall Services Module
Alternatively, you can also apply the ICMPACL access list to the destination interface to allow ICMP
traffic back through the FWSM.
Step 4
Ping from the host or router through the source interface to another host or router on another interface.
Repeat this step for as many interface pairs as you want to check.
If the ping succeeds, you see a system log message confirming the address translation for routed mode
(305009 or 305011) and that an ICMP connection was established (302020). You can also enter the
show xlate and show conns commands to view this information.
If the ping fails for transparent mode, contact Cisco TAC.
For routed mode, the ping might fail because NAT is not configured correctly (see
more likely if you enable NAT control. In this case, you see a system log message showing that the NAT
translation failed (305005 or 305006). If the ping is from an outside host to an inside host, and you do
not have a static translation (which is required with NAT control), you see message 106010: deny
inbound icmp.
The FWSM only shows ICMP debug messages for pings to the FWSM interfaces, and not for pings
Note
through the FWSM to other hosts.
Figure 26-5
MSFC

Disabling the Test Configuration

After you complete your testing, disable the test configuration that allows ICMP to and through the
FWSM and that prints debug messages. If you leave this configuration in place, it can pose a serious
security risk. Debug messages also slow the FWSM performance.
To disable the test configuration, perform the following steps:
To disable ICMP debug messages, enter the following command:
Step 1
hostname(config)# no debug icmp trace
To disable logging, if desired, enter the following command:
Step 2
hostname(config)# no logging on
To remove the ICMPACL access list, and also delete the related access-group commands, enter the
Step 3
following command:
hostname(config)# no access-list ICMPACL
(Optional) To disable the ICMP inspection engine, enter the following command:
Step 4
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Ping Failure Because the FWSM is not Translating Addresses
Ping
192.168.1.2
192.168.1.2
Host
192.168.1.1
FWSM
Testing Your Configuration
Figure
26-5). This is
26-5

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents