FWSM dropping packets of permit rules

Unanswered Question
Mar 6th, 2009


I'm having a strange issue with a FWSM ,

it has 4 networks ( inside , outside , dmz 1-2)

when i try to connect to an inside host from outside , fwsm denies the connection attempt, but the rule configured permits this traffic.

But when from the inside host I connect to the ouside host , traffic before denied now is permitted. I have modified antispoofing and others but I don't fix it

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Jon Marshall Thu, 03/12/2009 - 12:15

Sounds like you may have a NAT issue ie. when you connect from inside to outside you build a translation that can then be used from outside to inside.

Could you post the relevant portions of config for the NAT. Also could you detail the source and destination addresses on the inside and outside.


maller Thu, 03/19/2009 - 02:23

Hi Jon

yes... there was the command 'nat-control' enabled. I disabled it and now it works


This Discussion