I have just installed a pair of FWSM in two different Catalys 6509 in HA mode.
I left every access-list completely opened for test purposes. The stations connected to any inside interface can communicate with any other inside or outside station.
The problem is that from any station located outside is not possible to ping any FWSM inside interface. Every time a ping fails, the FWSM log is appended with a message like this:
Oct 09 2008 12:26:21: %FWSM-3-305006: portmap translation creation failed for icmp src outside:10.23.212.113 dst Subnet198:10.23.212.254 (type 8, code 0)
Unlike FWSM interfaces, when the outside station pings any inside station, it works.
I thik that I have all these items well defined:
- Static routing at both the FWSM and the Catalysts.
- Icmp permit any for every interface.
- The command same-security-traffic permit inter-interface is present.
- Access-lists completely opened and applyied to every interface.
The documentation states that the 305006 could be related to some static translations. But i was unable to overcome the problem by modifying the translations repeteadly.
I would be very grateful to anyone that could give any clue about this.