routing issue between two firewalls ??

Unanswered Question
Feb 13th, 2008
User Badges:


I have two FW, on is a ASA the other one is a FWSM they're conected to each other via a vlan. So each one of the 2 Fw have an interface on the same VLAN.

they are connected like this :

Fw( <-> 6500 (used only for layer 2 connectivity) <-> FWSMContext( <-> VRF{ FWSMContext( <-> Vlan interface( etc..}

From the Fw( I can ping FWSMContext( but I can't ping FWSMContext( and everything beyond in the VRF.

interfaces on th fwsm are :



The sh route on the FWSM looks like this :

S [1/0] via, DMZ_Outside

S [1/0] via, VRF_Inside

C is directly connected, VRF_Inside

S 1.1.3. [1/0] via, VRF_Inside

S [1/0] via, VRF_Inside

C is directly connected, DMZ_Outside

I checked the access-list but I don't see any hitcounts incremented on any of it when pinging the VRF_inside interface from Fw(

Does anybody have any idea about what could be the reason of this issue?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
jbayuka Wed, 02/20/2008 - 08:44
User Badges:
  • Bronze, 100 points or more

Routing is a critical part of almost every IPsec VPN deployment. Be certain that your encryption devices such as Routers and PIX or ASA Security Appliances have the proper routing information to send traffic over your VPN tunnel. Moreover, if other routers exist behind your gateway device, be sure that those routers know how to reach the tunnel and what networks are on the other side.

Refer to for more information


This Discussion