Cisco Firewall :: FWSM V 4.1.3 Forwarding Packets To Sender MAC Address

Feb 26, 2011

Does the FWSM v 4.1.3 is capable to forward return packets to the MAC address that sent them to it first?

View 6 Replies


ADVERTISEMENT

Cisco Firewall :: 6509 - FWSM With Packets Dropped

Jun 9, 2013

I happen to noticed the FWSM was dropping packets at about 387 packets every 5 minutes. My outside FWSM is WAN facing and has a 1gig link (35% utilized) my inside facing has about 100 downstream switches to the closets. I do not see my 6509's back plane is being over utilized and my understanding of the FWSM show be go for 5 gig so it isn't oversubscribe. Why i am seeing packets dropped?

[Code] ......

View 2 Replies View Related

Cisco Firewall :: Cat6500 FWSM Active / Standby IP Address

Jul 24, 2011

I have 2 FWSM running on 2 Cat6500 chassis, they work as a Active/Stanby group. Firewall mode is transparent. [code] HA is running well, but I can not ping the standby IP (10.98.1.248). So what could be the problem?

View 3 Replies View Related

Cisco Firewall :: ASA 5505 Port Forwarding With Different IP Address

Dec 27, 2011

I have Cisco ASA 5505 Firewall with security plus license, Currently I open ports on 25,80,443 on public  IP address 1.1.1.1 and perform static nat between the inside and outside IP address Such as i configured via CLI
  
access-list OUT_IN extended  permit tcp any host 1.1.1.1 eq  80
access-list OUT_IN extended  permit tcp any host 1.1.1.1 eq  443
access-list OUT_IN extended  permit tcp any host 1.1.1.1 eq  25

[Code]......

View 1 Replies View Related

Cisco Firewall :: ASA 5520 Address Translation And Port Forwarding

Oct 31, 2011

I am trying to correctly configure our ASA 5520 and our Mitel Border Gateway in our DMZ.  In the documentation for the Mitel border gateway it wants me to set up 2 external IP's on my ASA one to allow 443 traffice into the MBG, and another for 443 traffic that needs to be forwarded to port 4443 for the MGB in the DMZ.  My problem is I don't know how to do this. the MBG only has one IP, and I need to have 2 different URL's mapped to two different external IP's both externally using port 443, and one of them forwarding to 4443 on the DMZ interface.

View 10 Replies View Related

Cisco Firewall :: 3074 Port Forwarding For A Single IP Address

May 28, 2013

I need the following ports forwarded for a single ip address Port 88 (UDP)Port 3074 (UDP and TCP)Port 53 (UDP and TCP)Port 80 (TCP) .Is there an easy way to to it with service objects/groups?

View 7 Replies View Related

Cisco WAN :: 6506-E Randomly Not Forwarding Packets?

May 3, 2011

I have a 6506-E here that randonly drops packets and I'm trying to find out why.
 
When debugging ip packets (debug ip packet 52), I found a whole lot of these:
 
May  4 22:42:14: pak 5007BF54 consumed in input feature , packet consumed, MCI Check(55), rtype 0, forus FALSE, sendself FALSE, mtu 0May  4 22:42:14: pak 5008C488 consumed in input feature , packet consumed, MCI Check(55), rtype 0, forus FALSE, sendself FALSE, mtu 0May  4 22:42:14: pak 46A3E474 consumed in input feature , packet consumed, MCI Check(55), rtype 0, forus FALSE, sendself FALSE, mtu 0
May  4 22:42:14: pak 5007624C consumed in input feature , packet consumed, MCI Check(55), rtype 0, forus FALSE, sendself FALSE, mtu 0
 
The problem with this is, today's date is the 5 May.   The clock on the device shows the right time, but these debugs aren't.

View 2 Replies View Related

Cisco Switching/Routing :: 3750x 24s Not Forwarding Packets

Mar 1, 2013

We have a 3750x 24s acting as a root switch for about 10 other 3750x's. Everything else seems fine, but the device stopped forwarding packets to the applied static route. [code]

View 3 Replies View Related

Cisco Switching/Routing :: To Use DFC3 6500 For Forwarding Packets

May 31, 2012

From everything I read it seems like DFC is for forwarding packets.  When I hear packets I think of layer3.  If my 6500s are just being used as a big layer2 only switch do I need a DFC?  I am being told the 6500 looks at the layer 2 frame and the layer 3 patch header information before forwarding the frame.  How true is this?

View 1 Replies View Related

Cisco Switching/Routing :: Forwarding IEEE 802.3 Raw Packets Through 2960G Switch

Dec 5, 2011

I have a requirement to monitor downstream data feed from a remote site and feed it to multiple destination devices for recording.  The source data will be fed into a port on a Cisco 2960G switch then, using the monitor function, be forwarded to multiple interfaces.   This works fine for normal Etherent II traffic.  We tried a test using a device that generates IEEE 802.3 Raw packets ('type' field is used as a 'length' field) but found that while the traffic appeared to be accepted by the input port with no errors it was not forwarded to the destination ports, even when using the monitor function.  I did try the 'encapsulation replicate' feature with no luck.  It does not forward these packets even if I set all the ports into a common VLAN and let the switch just perform a normal switch function (non monitor).
 
if it is possible to get the IEEE 802.3 raw packets to pass through the switch and if it is, how to or what I need to do to make it work?

View 13 Replies View Related

Linksys Wireless Router :: WRT54GX2 - Port Forwarding For Wake On Lan Packets?

Nov 13, 2006

I just switched to a Linksys WRT54GX2 wireless Router from an older Netgear product.

View 5 Replies View Related

Find OS And Browser Of Sender Using Email Header?

Sep 4, 2012

How to find OS and browser of sender using email header?

View 1 Replies View Related

Cisco Switching/Routing :: X4648-rj45V+E Module Not Forwarding Frames / Packets In 4507E Switch?

Mar 26, 2012

I have a problem with x4648-rj45V+E module, which is not forwarding frames/packets in my 4507E switch. I have done the diagnostic and the module test is passed. When i try to ping from one PC to another in the flat network, icmp is not forwarding. Even i cannot see the mac addresses in the mac address-table. But i can ping to my management port in the sup module?

View 12 Replies View Related

Cisco Firewall :: 6500 - FWSM - Not Passing Traffic Through Firewall

May 3, 2011

We have 2 FWSM modules in each 6500 switches. 1st module is having 04 firewall vlan groups with 18 vlan interfaces in a single context firewall. All are working fine with no issues. Recently we create one more vlan on MFSC and add into the same firewall module. However newly created vlan inside the FW is not able to communicate with outside and also outside users not able to reach newly created subnet. But within the firewall zones (other interfaces) it can communicate. Once we did packet capture we noticed that its hitting firewall outside interface only and when we ping we got TTL expired error. we have default routes to outside and there's no any route inside as new segment is within the firewall (no any hop).
 
I guess there's no limitation on number of vlans that we can assign on one firewall eventhough there is a limitation for number of vlan-group which is 16 max (but we are within that limit).

View 2 Replies View Related

Cisco Switching/Routing :: Catalyst 3560 Switch Won't Forward Packets To Or From MAC Address

Aug 9, 2012

I have some Ethernet-connected cameras that all have the same Ethernet MAC address FF:FF:FF:0A:0A:0A. They were originally designed to directly connect to a Windows PC, but they can also connect through a simple unmanaged switch.A Catalyst 3560 switch won't forward packets to or from anything with that MAC address, at least not by default. Is there a way to convince the switch to do so?
 
It was my hope to replace the dedicated connections we have for these cameras with a separate VLAN for each camera, and switch them through our existing switch network. Given that all of the cameras use the same MAC address, putting them on the same network is out of the question, but different VLANs, where the only two devices on each VLAN were the camera and the PC that uses it, would be fine.
 
The switches run IOS 12.2(55) SE through SE3. I learned the camera MAC address from the PC's ARP table while the camera software runs; it turns out the cameras don't have a full IP stack either and don't even do ICMP.

View 2 Replies View Related

Cisco Routers :: RV042 / Forward All Packets To Port 9000 From WAN To Single IP Address On Network?

Nov 2, 2011

I have a RV042 using (for now), just the single WAN interface. I am trying to forward all packets to port 9000 from the WAN to a single IP address on the network.  I've set up both forwarding rules under Setup -> Forwarding and under the Firewall -> Access Rules.I cannot connect to my device from the outside world, however.  Is there something I'm missing?

View 4 Replies View Related

Cisco Firewall :: Difference Between ASA-SM1 And FWSM

Apr 1, 2013

Can any1 tell me wat is the difference between ASA-SM1 and FWSM.

View 2 Replies View Related

Cisco Firewall :: FWSM Upgrade From 4.0(4) To 4.1(8)?

Apr 10, 2012

I want to upgrade a pair of FWSM in active failover from 4.0(4) to 4.1(8) i just want to double check the process. i have tftp access to the primary at the minute. i cannot access the same tftp server with the standby. do i need flip over to the standby to be able to tftp the image across?
 
failover activehostname# changeto system 
hostname# copy tftp://x.x.x.x/c6svc-fwm-k9.4-1-8.bin flash:image
hostname# copy tftp://x.x.x.x/asdm-622f.bin flash:asdm
 hostname# reload 
 
Once i have the images loaded i reload both at the same time?[URL]

View 4 Replies View Related

Cisco Firewall :: FWSM Upgrade 3.2 To 4.0.4 For VSS?

Dec 17, 2011

I am planning for an VSS in Core but firstly I need to upgrade FWSM which is at 3.2 Ver to 4.0.4 (min release) I have checked software dependencies but not sure about Hardware Dependency  on Fwsm and Chassis for Eg. Rommon Upgrade on Chassis.

View 7 Replies View Related

Cisco Firewall :: Upgrading Fwsm From 3.1(11) To 4.x?

Jun 26, 2011

I wanna upgrade FWSM Version 3.1(11) to latest 4.x version is this possible or i have to upgrade first to 3.2 and then to 4.x?

Is there any changes in configuration commands that i need to know? The version that 6500 running is s72033-advipservicesk9_wan-mz.122-18.SXF14.bin,an upgrade to 6500 is needed also?And if so what ios version will i put?Also which is the asdm supported version?

View 3 Replies View Related

Cisco Firewall :: FWSM ACL / NAT With 6503

Jan 15, 2012

We recently deployed a FWSM on our 6503-e boxes (w/ sup720).  NAT is working (PAT) but the issue I am seeing is private traffic from remote sites is not being allowed through the FW.   I was able to get the remote site to ping the FWSM itself (inside address), but no hosts behind it.  Maybe an ACL issue? Also when I turn off NAT on the remote end, I can than access everything (We are NATng on both ends).   Im a routing guy by nature so I will defer this to the security guys out there.
 
Topology
 
Hosts (inside/10.15.25.0/24) > FWSM  (outside/public IP) -> Core Router -> MPLS CLOUD -> Core Router (NATng) - > Hosts (192.168.1.0/24)

ACLs applied to inside/outside interface
 
FWSM# show access-list ATX-ALLOW-IN
access-list ATX-ALLOW-IN; 15 elements
access-list ATX-ALLOW-IN extended permit tcp any any (hitcnt=222)
[Code]....

View 3 Replies View Related

Cisco Firewall :: 6500 - FWSM And ACE S/W Compatibility

Aug 14, 2011

We have a pair of 6500s with Sup720 running 12.2(33)SXI3. Each has an ACE-20 (s/w A2(2.0)) and FWSM (s/w v3.2(15)). We have reached a limit on the number of rules we can configure on the FWSM, and have determined that we shall upgrade to 4.1(5), with ASDM to 6.2(2)F. A question has been raised regarding the s/w on the ACE-20 modules. Do we need to upgrade them as well?

View 2 Replies View Related

Cisco Firewall :: ASA 8.3 And Higher Compared To FWSM

Oct 1, 2012

ASA code 8.3 and higher uses NAT objects and totally changes the NAT rule config. I am new to FWSM .... but was wondering if this comparable ? I am lookinig at upgrading FWSM 3.1(16) to a higher 4.1 version .... but have a feeling this could be a huge task if NAT config changes as with the ASA's

View 2 Replies View Related

Cisco Firewall :: How To Configure A FWSM By ASDM 6.2f

May 11, 2012

am trying to config a FWSM by ASDM 6.2f.there are formerly configured interfaces and new interfaces i created.when i add a new access rule it gets added only to all the old interfaces but not to the new ones i created.
 
1. what wrong with the new interfces i created?

2. whats the logic of auto adding a rule to "all" interfaces , the rules are incoming rules  specific to interfaces or groups , why add the to the rule to  "all" intefaces?.

View 3 Replies View Related

Cisco Firewall :: Upgrade From FWSM To ASA 5555Xs?

May 22, 2013

We would like to decommission our FWSMs and upgrade to the ASA 5555Xs. This leads me to ask the following: What would be the most efficient way of doing this without any interruption to production? How to successfully accomplish this?

View 1 Replies View Related

Cisco Firewall :: FWSM (in 6509) Is Not Coming Up?

Oct 29, 2012

our FWSM (in 6509) is not coming up, when tried to sesssion up using "Session slot 1 proc 1" command,It is giving error , "Tyring 127.0.0.11 .....connection timed out remote host not responding".
 
In "show mod" command output at Switch in IOS console:  under Card Type Section:  it is showing Model & Serial Number correctly,  Under MAC address sectino: displaying some MAC address But in Online Diag Status, it showing "Unknown" for Module 1.
 
We tried re-seating in other slots, but of no use. Giving same error. Some of other forms are saying it is the issue with 128 Mb CF image problem, FWSM is no more reachable from 6509 IOS console. We even tried using FWSM console (using PC-Conse & LCP Console) but FWSM is not contactable. 

View 1 Replies View Related

Cisco Firewall :: Unable To Login In FWSM 3.2

Apr 13, 2011

I  am having two dc switches with FWSM modules installed. DC switch1 FWSM  (Ver 3.2(12) is wokring as active and Secondary DC switch2 FWSM (ver  3.2.(12) is in standby mode.
 
From  yesterday I am trying to login primary FWSM, It is accepting my  username and credentials but prompting again for username please refer  below
 
DXB-DC1>session slot 5 p 1The default escape character is Ctrl-^, then x.You can also type 'exit' at the remote prompt to end the sessionTrying 127.0.0.51 Open. [code]

View 1 Replies View Related

Cisco Firewall :: FWSM Reset With 6500

Feb 3, 2012

I have had a strange issue with a pair of FWSM's in 2 6500's, it seems there was a failover but both module's have been reset.
 
CAT1
Feb 03 17:08:46.525: %SNMP-5-MODULETRAP: Module 8 [Down] Trap Feb 03 17:08:46.522: SP: The PC in slot 8 is shutting down. Please wait ...Feb 03 17:09:01.525: SP: shutdown_pc_process:No response from module 8 Feb 03 17:09:11.382: %C6KPWR-SP-4-DISABLED: power to module in slot 8 set off (Reset) Feb 03 17:10:56.093: %DIAG-SP-6-RUN_MINIMUM: Module 8: Running Minimal Diagnostics...Feb 03 17:10:59.796: %SVCLC-5-FWVTPMODE: VTP
[Code]...

View 1 Replies View Related

Cisco Firewall :: Can Upgrade FWSM 4.0.3 To 4.0.17 With Chassis IOS

Jul 9, 2012

Can I upgrade FWSM 4.0.3 to 4.0.17  with Chassis IOS s72033-adventerprisek9_wan-mz.122-33.SXH4.bin ?
 
In chassis's slot we have ACE and FWSM slot also. if I will upgrade chassis it will reboot ACE too.I do not want to reload Chassis.

View 2 Replies View Related

Cisco Firewall :: C6509 - Can't Connect FWSM

Sep 27, 2012

I'm running two C6509 Chassis with FWSM and ACE module install on each chasiss.I have no problem with session into 1 FWSM and 2 ACE modules.But 1 FWSM module can't be access by session command.As I understand two FWSM module status is OK, and working fine.When I tried to session into FWSM, I got these messages..
 
[code]....

View 2 Replies View Related

Cisco Firewall :: How To Upgrade Fwsm Image From 3.1(10) To 4.0(8)

Jan 11, 2010

I need to upgrade the fwsm image from 3.1(10) to 4.0(8). Can i do it directly from 3.1(10) to 4.0(8) ?Do i need to upgrade other image also along with Firewall version 4.0(8)?
 
[code]....

View 5 Replies View Related

Cisco Firewall :: 6509 - FWSM Log Messages

Jul 16, 2011

I think I got a strange behavior on a context of my WS-SVC-FWM-1 (on a Catalyst 6509 running IOS 12.2(18)SXF17a) that is running FWSM Firewall Version 4.1(3). This context sends these log messages every ten minutes:
 
Jul 17 2011 23:31:16: %FWSM-6-302010: 0 in use, 0 most used
Jul 17 2011 23:31:17: %FWSM-6-302010: 2245 in use, 107133 most used
[code]...
 
If I issue the "show conn" three seconds later the log message, the output I got is: FWSM#   sh conn 1041 in use, 107133 most used
 
In another context on the same FWSM the log message sent every ten minutes is just this one:
 
Jul 17 2011 23:31:17: %FWSM-6-302010: 1358 in use, 72503 most used
Jul 17 2011 23:41:22: %FWSM-6-302010: 1590 in use, 72503 most used
 
In this case there is no the log message where the "in use" field and "most used" field are 0 (zero). why does the context send the message with the "in use" field and "most used" field 0 (zero).

View 1 Replies View Related

Cisco Firewall :: 6509 / 2811 - NAT At FWSM

May 17, 2011

I have attached a drawing of our network.  We have two 6509's connected to two Cisco 2811 (onsite) that the ISP owns. I am trying to get one side up and running before I worry about redundancy and so forth.  For this reason I have set all the HSRP priorities to 110 on the left 6509.  I have HSRP running between the ISP routers and V LAN 101 of the 6509's.  This works as I can ping yahoo and Google just fine from the 6509 switch.  I can't get from my laptop connected to V LAN 23 to the internet. 

It doesn't even attempt to NAT as there are no translations.  I have public address assigned by my ISP configured between the ISP routers and my 6509 on V LAN 101.  I then have the public address assigned to V LAN 100.  I configured V LAN 100 on the switch and V LAN 100 on the FWSM with the IP address in the drawing.  I have my NAT statements and route in my FWSM according to the drawing as well.  On the switch, I have a default route to X.X.12.19 which is the VIP between the ISP routers.  I can reach anything on the inside of my network, including the old network addresses from V LAN 23.  
 
1. Is it best to do NAT at the FWSM or should I do it on the MSFC connected to the ISP routers?  
2. If I have to configure NAT at the FWSM, does this requires me to extend the public network down to the FWSM? 
3. I'll take any examples you may have as I am stuck.

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved