Cisco 7604 Configuration Manual page 611

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 26
Troubleshooting the Firewall Services Module
Symptom
Possible Cause
Recommended Action
FWSM" section on page
Symptom
Possible Cause
source and destination interfaces.
Recommended Action
allow returning traffic through. In addition to an access list on the source interface, you either need
to apply an access list to destination interface to allow replying traffic, or enable the ICMP
inspection engine, which treats ICMP connections as stateful connections.
Symptom
interface.
Possible Cause
through. Unlike the PIX firewall, the FWSM does not automatically allow traffic to pass between
interfaces.
Recommended Action
"Adding an Extended Access List" section on page
Symptom
Possible Cause
same security level.
Recommended Action
Interfaces on the Same Security Level" section on page
Symptom
Possible Cause
Recommended Action
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
You cannot ping the FWSM interface.
You did not enable ICMP to the FWSM.
Enable ICMP to the FWSM according to the
23-9.
You cannot ping through the FWSM, even though the access list allows it.
You did not enable the ICMP inspection engine or apply access lists on both the
Because ICMP is a connectionless protocol, the FWSM does not automatically
Traffic does not go through the FWSM from a higher security interface to a lower security
You did not apply an access list to the higher security interface to allow traffic
Apply an access list to the source interface to allow traffic through. See the
Traffic does not pass between two interfaces on the same security level.
You did not enable the feature that allows traffic to pass between interfaces on the
Enable this feature according to the
When the FWSM fails over, the secondary unit does not pass traffic.
You did not assign the same VLANs for both units.
Make sure to assign the same VLANs to both units in the switch configuration.
"Allowing ICMP to and from the
13-6.
"Allowing Communication Between
6-10.
Common Problems
26-11

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents