Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

FWSM NAT misbehavior

Unanswered Question
Jan 26th, 2006
User Badges:


I have a FWSM 2.3.1 on routed mode running on 6509 with switch on IOS.I am routing between two networks through FWSM as

I am doing NAT bypass to communicate between int1 and int2.Security level for int1 is higher than int2

the related config for this is as follows.

ip address int2

static (int1,int2) netmask

route int2

The configuration works fine but suddenly the subnet becomes unreachable from FWSM and 192.168.130/24 network.

when i check the xlates i find.

Global Local

Global Local

Global Local

The first 2 lines are not expected in normal scenarios as i should only be getting the third line.

The network becomes reachable as soon as i clear the translations for network.

Any idea why this is happening?



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
smalkeric Wed, 02/01/2006 - 14:23
User Badges:
  • Silver, 250 points or more

On the FWSM, you must specifically configure some interfaces to either use or to bypass NAT. For example, when hosts on a higher security interface (inside) access hosts on a lower security interface (outside), you must configure NAT on the inside hosts or specifically configure the inside hosts to bypass NAT .



This Discussion