Cisco Firewall :: Running 10Gig Traffic Through FWSM On C6509

Oct 30, 2011

Our customer is experimenting really bad performance when running 10Gig traffic through FWSM on C6509. Test with1 Gig traffic are providing find result perfromance as expected in this document: url... I have made a simple drawing so everyone can understand the setup:
 
The issue is when running 10 Gig traffic between Netapp servers. This traffic is going though the FWSM and the perfomance are really bad: around 50 Mbit/sec. If the traffic is not going though the FWSM ther performance are around 900 Mbit/s.
 
The customer and I think that the issue is releated the buffer in the C6509 and the FWSM which has big trouble managing 10G to 1G traffic convertering between C6509 and FWSM 6 G etherchannel connection.
 
When running 10G traffic through FWSM the number of output drops are increasing as you can see on the output bellow. The last thing which is wired a is that the speed is showing 1000 Mbits and not 6000Mbits. [code]

View 4 Replies


ADVERTISEMENT

Cisco Firewall :: C6509 - Can't Connect FWSM

Sep 27, 2012

I'm running two C6509 Chassis with FWSM and ACE module install on each chasiss.I have no problem with session into 1 FWSM and 2 ACE modules.But 1 FWSM module can't be access by session command.As I understand two FWSM module status is OK, and working fine.When I tried to session into FWSM, I got these messages..
 
[code]....

View 2 Replies View Related

Cisco Firewall :: Will FWSM 3.1(20) Run With VS-S720 Running Native

Jun 26, 2012

I am about to replace the supervisor engine in our pair of distribution switches in our data center. We currently have a FWSM module installed in each of my distribution switches running 3.1(20) code. The old sup720 are running 8.6(4) and the mfsc are running 12.2(17d)SXB11a. I am wondering about the compatibility of running the FWSM with the same code after installing the new VS-S720 modules. I do not plan on configuring virtual switch yet and did plan on upgrading the FWSM to 4 code train but just not immediately. Will I be able to run my FWSM using the current 3.1(20) code after I install my new VS-S720 running in native mode?
 
If I have to upgrade the FWSM then I need to know if I have to upgrade the module in each distribution switch at the same time? Furthermore I do not believe that the FWSM 4 code is supported in hybrid mode, which means that I will have to convert to native before upgrading to FWSM 4 before I install the VS-S720 in one of my distribution switches. Currently the FWSM modules are in active/standby mode in different chassis.
 
I had planned to install the VS-S720 module in one of my distribution switch and do the other installation a week later. I would rather not have to convert to native and upgrade the FWSM modules in both distribution switches during the first switch upgrade.

cnDS02> (enable) sh mod    
Mod Slot Ports Module-Type               Model               Sub Status
--- ---- ----- ------------------------- ------------------- --- --------
1   1    16    1000BaseX Ethernet        WS-X6516A-GBIC      no  ok
2  .... Please refer to Detail Note. cnDS02> (enable) sh mod    

[code]....

View 1 Replies View Related

Cisco Firewall :: WCCP Support On FWSM Running 6500

Mar 10, 2011

What the support for WCCP on a FWSM running 4.0(7) is like, if there is any at all ?
 
I've read that the earliest PIX release that supports WCCP was 7.2(1) but I'm not sure how FWSM 4.0(7) aligns with the PIX versions.The only doc's i can find refrencing WCCP on a 6500 with FWSM is in the 6500 12.2 IOS guide.

View 1 Replies View Related

Cisco Firewall :: 6500 - FWSM - Not Passing Traffic Through Firewall

May 3, 2011

We have 2 FWSM modules in each 6500 switches. 1st module is having 04 firewall vlan groups with 18 vlan interfaces in a single context firewall. All are working fine with no issues. Recently we create one more vlan on MFSC and add into the same firewall module. However newly created vlan inside the FW is not able to communicate with outside and also outside users not able to reach newly created subnet. But within the firewall zones (other interfaces) it can communicate. Once we did packet capture we noticed that its hitting firewall outside interface only and when we ping we got TTL expired error. we have default routes to outside and there's no any route inside as new segment is within the firewall (no any hop).
 
I guess there's no limitation on number of vlans that we can assign on one firewall eventhough there is a limitation for number of vlan-group which is 16 max (but we are within that limit).

View 2 Replies View Related

Cisco Firewall :: 6509-E / Traffic Coming From GRE Interface And Going Further Through FWSM?

Oct 4, 2011

I have problem with traffic coming from GRE interface and going further through FWSM on the same 6509-E chassis.It's very interesting and confusing. If packets are fragmented, I can go through, however, if I use normal packets (usual ping for example) traffic goes from outside to inside and stops on it's way back.
 
Here is the detailed info:
WS-C6509-E with WS-SUP720-3B
FWSM HW 4.0,  SW 4.1(4) 
 
GRE is done in hardware (source is loopback interface - only one loopback per GRE tunnel).

View 5 Replies View Related

Cisco Firewall :: 6513 / All Traffic Move Via FWSM (Transparent Mode)

Apr 18, 2013

As I am planning to deploy FWSM Module in 6513 chassis and need your valuable comments regarding the strategy that I create for this deployment.Initially (Without FWSM Deployment) all internal traffic moves in this manner.
 
7613(G9/5) --> 6513(G10/4) --> ISA (Internal Int.) [NATing] (ISA External Int.) -->
6513(G9/45){This is L2 port in VLAN 164} --> VLAN 164(SVI Int,IP:192.168.40.20) -->
(G9/44){This is L2 port in VLAN 164}--> ASR 1002 -->Router -->Internet.
 
As you can see from the Image that I am planning to deploy FWSM in transparent mode in between VLAN 164(SVI Int,IP:192.168.40.20) -[FWSM here]->(G9/44){This is L2 port in VLAN 120}By putting Inside interface of FWSM in VLAN 164 and create a new VLAN  on 6513 i.e VLAN 120 and put G9/44 in it.know will this configuration will work regarding the passing of traffic through FWSM ? what improvement I have to made in this design. You can check the attached diagram.

View 3 Replies View Related

Cisco Firewall :: 7609 - VLAN Traffic Is Not Reaching Upto FWSM

Nov 11, 2011

I have FWSM v4.0 installed on Cisco 7609 router and when I want to configure FWSM services on it, VLAN traffic is not passing through the FWSM or not Reaching upto fwsm

View 1 Replies View Related

Cisco Firewall :: ASA 5505 - VPN Up And Running But No Traffic

Oct 27, 2011

I have VPN up and running between two sites. Both sites have Cisco ASA 5505. I can ping across the devices from both networks. But I cannot remote into the servers on the other network.

View 8 Replies View Related

Cisco Firewall :: ASA 5585 / SSP 40 - 10Gig Interface Needed For Log Server

Apr 26, 2013

We have deployed a few ASA 5585 SSP40 in our data centers to seperate different customer/security zones connected with 10Gig interfaces. Currently we have a dedicated log server attached to each ASA connected with a p2p 10Gig interface. While detailed log information is considered important I somehow have the gut feeling all this high end equipment and bandwidth is used a little too wasteful. I have little experience with these big firewalls and I have not yet seen the equipment in an attack situation, however I doubt a firewall could ever generate 10gig of log data, while doing the primary fire walling job at the same time. Looking at the typical packet size of a syslog message I don't even believe a 1 gig link could ever be saturated with pure syslog messages.

View 3 Replies View Related

Cisco Switching/Routing :: Monitor ICMP Traffic On C6509?

Dec 22, 2011

Both regular IP traffic and ICMP traffic are passing through the source port. C6509 provides the option of filtering vlan traffic during monitoring. But I don't have vlan traffic.
 
qa-c6509-c(config)#monitor session 1 filter ?  vlan  SPAN filter VLAN
 
So I applied an access-list which only allows icmp traffic to be sent out of the monitoring port. But it does not work.

View 4 Replies View Related

Cisco Firewall :: 5580-40 - Input Errors / Overruns And Reset Drops On 10Gig Interface?

May 10, 2012

I have an issue with input errors, overruns, and input reset drops on the inside interface of an 5580-40 (v8.2.5: Transparent mode)  The box is not stressed at all according to the 'show' commands in the Cisco troubleshooting performance document for PIX/ASA v8.2.5.  Nothing stands out because is pretty much normal, nothing (processes, RAM, blocks, IO...) really being highly utilized.  I have replaced the 10Gig card and that seemed to work because the rate of errors has gone down tremedously.  The next step is to RMA the whole box.My question is what would be the cause of the inside interface to stop processing traffic (I say that because the syslog server stops receiving messages) for some periods of 30 seconds periodically throughout the day and clients lose their connections (ie Outlook, IBM Sametime, Oracle, MSSQL..etc).  Can the issue be somewhere related to the overruns and input errors?

View 2 Replies View Related

Cisco WAN :: 7613 - Traffic Move From Msfc To Fwsm?

Apr 4, 2013

I am planning to deploye the fwsm with all this complexity, will this type of senario work or not means traffic will move from msfc to the core.. Is this right to create another svi int2 on msfc to move traffic from msfc to core-switch.
 
G0/1(cisco7613) Vlan10----Vlan10(inside)FWSM-(outside)vlan20---Vlan20(inside)(svi-int1)MSFC(outside)(svi-int2)Vlan30---Vlan 30G0/2(Core-Switch)-----internet--->

View 5 Replies View Related

Cisco Firewall :: Configuration Migration From ASA 5540 Running 7.2 To 5525X Running 9.1

May 7, 2013

I need to replace an existing ASA 5540 with a new ASA 5525X. I would like to pre-stage and configure the new box with the existing config, migrate license and export certificate files before swapping it with the old one during a change window. The new firewall will run 9.1 on deployment. Now the same 7.2(4) cannot just be copied over to 5525X running the minimum 8.6 version. There is a Web based tool available at [URL] according to Cisco documentation but the page does not load for me (Cisco intranet only tool ?). Is there another tool for automatic conversion ?

View 3 Replies View Related

Security / Firewalls :: Allow Traffic Through Computer On Home LAN Running ZA

May 18, 2012

I am trying to reconfigure my Boblite modem router to allow basically all traffic through to my computer on my home lan which is running ZA so I can see what intrusion attempts whether directly or indirectly are being made on my connection.I am not having much luck at the moment, have tried turning off the firewall within the router all together and also setting up a dmz for my computer.

View 1 Replies View Related

Cisco Switching/Routing :: Nexus 5k To 2k To 10gig Server Connectivity?

Nov 11, 2012

We are in the plan of implementing a new 10gig network. For this we have chosen the Nexus 5596 and 2232 pair. What are the transceivers/accesories I should order for connecting 10Gig servers of NC552SFP dual port NICs to the 2232 in High availability (NIC 1 to 2232PP 1 and NIC 2 to 2232PP 2). Should I order the FEX SFP+ uplink conector to conect 5k and 2232 also (or its aded to the Nexus box itself) ? Also, is it fine to have Nexus 2232 in floor 2 and Parent neus in Floor 3 (say seperatd by a max of 400meters)?

View 1 Replies View Related

Cisco Routers :: Unable To Isolate DMZ And LAN Traffic With SA520 Running 2.1.7.1 Firmware

Jan 29, 2013

I am unable to isolate DMZ and LAN traffic with an SA520 running 2.1.7.1 firmware.  I have the optional port configured as DMZ and DHCP server enabled.  I tired leaving the firewall as default.  Also tried creating firewall rules to deny traffic from LAN to DMZ and DMZ to LAN for any address and any service.I am still able to ping devices both from LAN to DMZ and DMZ to LAN.  I am also able to see network resources in both directions.

View 5 Replies View Related

Cisco Firewall :: Difference Between ASA-SM1 And FWSM

Apr 1, 2013

Can any1 tell me wat is the difference between ASA-SM1 and FWSM.

View 2 Replies View Related

Cisco Firewall :: FWSM Upgrade From 4.0(4) To 4.1(8)?

Apr 10, 2012

I want to upgrade a pair of FWSM in active failover from 4.0(4) to 4.1(8) i just want to double check the process. i have tftp access to the primary at the minute. i cannot access the same tftp server with the standby. do i need flip over to the standby to be able to tftp the image across?
 
failover activehostname# changeto system 
hostname# copy tftp://x.x.x.x/c6svc-fwm-k9.4-1-8.bin flash:image
hostname# copy tftp://x.x.x.x/asdm-622f.bin flash:asdm
 hostname# reload 
 
Once i have the images loaded i reload both at the same time?[URL]

View 4 Replies View Related

Cisco Firewall :: FWSM Upgrade 3.2 To 4.0.4 For VSS?

Dec 17, 2011

I am planning for an VSS in Core but firstly I need to upgrade FWSM which is at 3.2 Ver to 4.0.4 (min release) I have checked software dependencies but not sure about Hardware Dependency  on Fwsm and Chassis for Eg. Rommon Upgrade on Chassis.

View 7 Replies View Related

Cisco Firewall :: Upgrading Fwsm From 3.1(11) To 4.x?

Jun 26, 2011

I wanna upgrade FWSM Version 3.1(11) to latest 4.x version is this possible or i have to upgrade first to 3.2 and then to 4.x?

Is there any changes in configuration commands that i need to know? The version that 6500 running is s72033-advipservicesk9_wan-mz.122-18.SXF14.bin,an upgrade to 6500 is needed also?And if so what ios version will i put?Also which is the asdm supported version?

View 3 Replies View Related

Cisco Firewall :: FWSM ACL / NAT With 6503

Jan 15, 2012

We recently deployed a FWSM on our 6503-e boxes (w/ sup720).  NAT is working (PAT) but the issue I am seeing is private traffic from remote sites is not being allowed through the FW.   I was able to get the remote site to ping the FWSM itself (inside address), but no hosts behind it.  Maybe an ACL issue? Also when I turn off NAT on the remote end, I can than access everything (We are NATng on both ends).   Im a routing guy by nature so I will defer this to the security guys out there.
 
Topology
 
Hosts (inside/10.15.25.0/24) > FWSM  (outside/public IP) -> Core Router -> MPLS CLOUD -> Core Router (NATng) - > Hosts (192.168.1.0/24)

ACLs applied to inside/outside interface
 
FWSM# show access-list ATX-ALLOW-IN
access-list ATX-ALLOW-IN; 15 elements
access-list ATX-ALLOW-IN extended permit tcp any any (hitcnt=222)
[Code]....

View 3 Replies View Related

Cisco Switching/Routing :: Nexus 7000 10Gig Card Not Seeing Transceiver Module?

Nov 13, 2011

I'm unable to get the N7K-M108X2-12L 10 Gbps Ethernet XL Module within our Nexus 7009 chassis to recognise the individual X2-10GB-SR transceiver modules. I have the same issue on another 7009 chassis.If I perform a 'show interface'. I get the following output saying SFP not inserted.
 
-Ethernet3/5 is down (SFP not inserted)
-Dedicated Interface
-Belongs to Po51
-Hardware: 10000 Ethernet, address: 7081.0599.d458 (bia 7081.0599.d458)
 
I also get the same result if I issue the following command.  Are their any additional features I need to enable? or would this be a license issue?
Have already tried different X2-10GB-SR modules, reloading the card, re seating the card. [code]

View 6 Replies View Related

Cisco Firewall :: 6500 - FWSM And ACE S/W Compatibility

Aug 14, 2011

We have a pair of 6500s with Sup720 running 12.2(33)SXI3. Each has an ACE-20 (s/w A2(2.0)) and FWSM (s/w v3.2(15)). We have reached a limit on the number of rules we can configure on the FWSM, and have determined that we shall upgrade to 4.1(5), with ASDM to 6.2(2)F. A question has been raised regarding the s/w on the ACE-20 modules. Do we need to upgrade them as well?

View 2 Replies View Related

Cisco Firewall :: ASA 8.3 And Higher Compared To FWSM

Oct 1, 2012

ASA code 8.3 and higher uses NAT objects and totally changes the NAT rule config. I am new to FWSM .... but was wondering if this comparable ? I am lookinig at upgrading FWSM 3.1(16) to a higher 4.1 version .... but have a feeling this could be a huge task if NAT config changes as with the ASA's

View 2 Replies View Related

Cisco Firewall :: How To Configure A FWSM By ASDM 6.2f

May 11, 2012

am trying to config a FWSM by ASDM 6.2f.there are formerly configured interfaces and new interfaces i created.when i add a new access rule it gets added only to all the old interfaces but not to the new ones i created.
 
1. what wrong with the new interfces i created?

2. whats the logic of auto adding a rule to "all" interfaces , the rules are incoming rules  specific to interfaces or groups , why add the to the rule to  "all" intefaces?.

View 3 Replies View Related

Cisco Firewall :: Upgrade From FWSM To ASA 5555Xs?

May 22, 2013

We would like to decommission our FWSMs and upgrade to the ASA 5555Xs. This leads me to ask the following: What would be the most efficient way of doing this without any interruption to production? How to successfully accomplish this?

View 1 Replies View Related

Cisco Firewall :: FWSM (in 6509) Is Not Coming Up?

Oct 29, 2012

our FWSM (in 6509) is not coming up, when tried to sesssion up using "Session slot 1 proc 1" command,It is giving error , "Tyring 127.0.0.11 .....connection timed out remote host not responding".
 
In "show mod" command output at Switch in IOS console:  under Card Type Section:  it is showing Model & Serial Number correctly,  Under MAC address sectino: displaying some MAC address But in Online Diag Status, it showing "Unknown" for Module 1.
 
We tried re-seating in other slots, but of no use. Giving same error. Some of other forms are saying it is the issue with 128 Mb CF image problem, FWSM is no more reachable from 6509 IOS console. We even tried using FWSM console (using PC-Conse & LCP Console) but FWSM is not contactable. 

View 1 Replies View Related

Cisco Firewall :: Unable To Login In FWSM 3.2

Apr 13, 2011

I  am having two dc switches with FWSM modules installed. DC switch1 FWSM  (Ver 3.2(12) is wokring as active and Secondary DC switch2 FWSM (ver  3.2.(12) is in standby mode.
 
From  yesterday I am trying to login primary FWSM, It is accepting my  username and credentials but prompting again for username please refer  below
 
DXB-DC1>session slot 5 p 1The default escape character is Ctrl-^, then x.You can also type 'exit' at the remote prompt to end the sessionTrying 127.0.0.51 Open. [code]

View 1 Replies View Related

Cisco Firewall :: FWSM Reset With 6500

Feb 3, 2012

I have had a strange issue with a pair of FWSM's in 2 6500's, it seems there was a failover but both module's have been reset.
 
CAT1
Feb 03 17:08:46.525: %SNMP-5-MODULETRAP: Module 8 [Down] Trap Feb 03 17:08:46.522: SP: The PC in slot 8 is shutting down. Please wait ...Feb 03 17:09:01.525: SP: shutdown_pc_process:No response from module 8 Feb 03 17:09:11.382: %C6KPWR-SP-4-DISABLED: power to module in slot 8 set off (Reset) Feb 03 17:10:56.093: %DIAG-SP-6-RUN_MINIMUM: Module 8: Running Minimal Diagnostics...Feb 03 17:10:59.796: %SVCLC-5-FWVTPMODE: VTP
[Code]...

View 1 Replies View Related

Cisco Firewall :: Can Upgrade FWSM 4.0.3 To 4.0.17 With Chassis IOS

Jul 9, 2012

Can I upgrade FWSM 4.0.3 to 4.0.17  with Chassis IOS s72033-adventerprisek9_wan-mz.122-33.SXH4.bin ?
 
In chassis's slot we have ACE and FWSM slot also. if I will upgrade chassis it will reboot ACE too.I do not want to reload Chassis.

View 2 Replies View Related

Cisco Firewall :: How To Upgrade Fwsm Image From 3.1(10) To 4.0(8)

Jan 11, 2010

I need to upgrade the fwsm image from 3.1(10) to 4.0(8). Can i do it directly from 3.1(10) to 4.0(8) ?Do i need to upgrade other image also along with Firewall version 4.0(8)?
 
[code]....

View 5 Replies View Related

Cisco Firewall :: 6509 - FWSM Log Messages

Jul 16, 2011

I think I got a strange behavior on a context of my WS-SVC-FWM-1 (on a Catalyst 6509 running IOS 12.2(18)SXF17a) that is running FWSM Firewall Version 4.1(3). This context sends these log messages every ten minutes:
 
Jul 17 2011 23:31:16: %FWSM-6-302010: 0 in use, 0 most used
Jul 17 2011 23:31:17: %FWSM-6-302010: 2245 in use, 107133 most used
[code]...
 
If I issue the "show conn" three seconds later the log message, the output I got is: FWSM#   sh conn 1041 in use, 107133 most used
 
In another context on the same FWSM the log message sent every ten minutes is just this one:
 
Jul 17 2011 23:31:17: %FWSM-6-302010: 1358 in use, 72503 most used
Jul 17 2011 23:41:22: %FWSM-6-302010: 1590 in use, 72503 most used
 
In this case there is no the log message where the "in use" field and "most used" field are 0 (zero). why does the context send the message with the "in use" field and "most used" field 0 (zero).

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved