Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

FWSM intervlan communication failing.

Hi ,

I have setup FWSM in my lab , and configured a security context named it "test" and configured 3 vlan interfaces on it. I have disabled the NAT between these interface traffic. below is the setup.

inside - /

inside-2 - /

outside -

From inside interface i am unable to ping inside-2 interface IP and viceversa, can somebody please adavice.

both are directly connected interface.


Re: FWSM intervlan communication failing.

by default a FWSM does not allow traffic between interfaces without an access-list applied unlike and ASA/PIX.

Cisco Employee

Re: FWSM intervlan communication failing.


Can you please provide the output of 'show nameif' and 'show ip addr'? If you are referring to pinging the actual IP address of the "far-side" interface, this is NOT supported on any Cisco Firewall, unlike Cisco routers.

If you are pinging hosts off of the interface (not the interface itself), the output of 'show nameif' as above will provide insight. If the two interfaces are at the same security level, it may also be 'same-security-traffic permit inter-interface'.

Hope this helps. If you still need assistance, please provide the output requested above.

New Member

Re: FWSM intervlan communication failing.

Please find the outputs below. permit inter-interface was already added.

FWSM/test# sh nameif

Interface Name Security

Vlan100 outside 0

Vlan101 inside 100

Vlan112 inside-2 100

FWSM/test# sh run | in permit inter

same-security-traffic permit inter-interface

FWSM/test# sh int ip br

Interface IP-Address OK? Method Status Protocol

Vlan100 YES CONFIG up up

Vlan101 YES CONFIG up up

Vlan112 YES CONFIG up up is another switch connected the FWSM. on vlan 112, below is the ping response.

FWSM/test# ping

Sending 5, 100-byte ICMP Echos to, timeout is 2 seconds:


Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms

FWSM/test# ping inside

Sending 5, 100-byte ICMP Echos to, timeout is 2 seconds:


Success rate is 0 percent (0/5)

Below is the log i get when I ping using inside interface. says no route, however these are directly connected routers.

Aug 17 2009 04:30:30: %FWSM-5-111008: User 'enable_15' executed the 'ping' command.

Aug 17 2009 04:30:41: %FWSM-6-110001: No route to from

Aug 17 2009 04:30:51: %FWSM-5-111008: User 'enable_15' executed the 'ping inside' command.

Re: FWSM intervlan communication failing.

that's definetly not a routing issue, why would you send the icmp traffic to out of inside interface when it's directly connected to inside-2.

please refer to this link

the " ping inside " tells the FWSM to reach via inside interface.


Cisco Employee

Re: FWSM intervlan communication failing.

As Vikram stated, the 'ping inside' command implies to send the ping out the inside interface. The FWSM maintains a route table on a per-interface basis. As a ping 'inside' command, we'll reference the route table for the 'inside' interface.

These route tables also come into play when a bad translation is formed through the FWSM. The route table for the egress interface will be referenced when processing the packet.

New Member

Re: FWSM intervlan communication failing.

Thanks Guys for the clarity on the command, i mistook this command for the cisco source interface option.

However I have been facing problems in ping between the servers connected to inside and inside-2 interfaces as mentioned in the 1st post of this netflow discussion.