Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

%FWSM-3-305006: portmap translation creation failed for icmp src outside

Unanswered Question
Mar 21st, 2010
User Badges:

Hi ,

I have configured my FWSM with no nat-control, simple routing mode, but i am getting following error log when i ping from host residing at the outside interface of FWSM to inside interface of FWSM, I know that inside interface of FWSM cannot be pingged as per FWSM design, but i need to know why i am getting this error.

4:11:38 Local4.Error Mar 07 2010 14:09:32: %FWSM-3-305006: portmap translation creation failed for icmp src outside: dst inside: (type 8, code 0)

interface Vlan99
nameif outside
security-level 0
ip address standby
interface Vlan57
nameif FWSM

security-level 85
ip address standby
interface Vlan6
nameif inside

security-level 90
ip address standby

interface Vlan67
nameif FWSM_2
security-level 80
ip address standby

route outside 1 (towards MSFC)

logging enable
logging timestamp
logging standby
logging emblem
logging console debugging
logging trap debugging
logging history debugging
logging asdm debugging

I would appreciate if some one can share the experince.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (1 ratings)
Kureli Sankar Sun, 03/21/2010 - 15:31
User Badges:
  • Cisco Employee,

Do you have

static (inside,outside) net

Also, pls. enable icmp inspection under the policy-map.


Jennifer Halim Sun, 03/21/2010 - 21:41
User Badges:
  • Cisco Employee,

Unfortunately there is no specific syslog messages for pinging the wrong interface of the fwsm. The syslog message that you are seeing will be the one generated for pinging the wrong interface of the firewall.

Nadeem ahmed Ahmed Sun, 03/21/2010 - 23:30
User Badges:

Hi halijenn ,

I am getting this message only when i ping to inside interface while no syslog message comes with other interfaces... Is it due to the most secure interface ? while other less secure interface are not giving any syslog message.

Please suggest if any!!



Jennifer Halim Sun, 03/21/2010 - 23:56
User Badges:
  • Cisco Employee,

Sorry, as per design, you can't ping the opposite interface of the firewall, whether it is ping from the outside host towards the inside or FWSM interface, OR/ ping from an inside host towards the outside interface or FWSM interface of the FWSM.

You can only ping as per the following:

- Ping through the FWSM, ie: from inside host towards outside host, and vice versa. In this case, you would need to configure "inspect icmp".

- Ping the direct FWSM interface, ie: from inside host, you can only ping the inside interface, from the outside host, you can ping the outside interface, etc.

Nadeem ahmed Ahmed Sun, 03/21/2010 - 23:27
User Badges:


I have disabled the Nat-control, FWSM is working in pure routing mode..?

Also what will be the use of enabling icmp inspection in my scenario.



This Discussion