I am facing an issue with a new 6500 router (IOS version 12.2 ) having a FWSM module. (FWSM Version 2.3(3)) which is like this:-
I have three Vlans INSIDE, OUTSIDE and DMZ with security levels 100, 0 and 50 respectively.I have created appropriate access control lists for pinging between Vlans ( INSIDE to DMZ ). But the hosts cannot ping.
However when i give the SAME security level to ALL VLANs ( INSIDE, OUTSIDE and DMZ) and give the command "
same-security-traffic permit inter-interface " , it works fine.
I am totally at a loss to understand this. This might be a workaround but , i guess the ideal situation is to give different sec levels to vlans and then control access.
Could some please advice on this issue.
Thanks & regards