We have the network designed and running as below.
Dual core 6500 as distribution switch
Fwsm as front end firewall
MPLS WAN router
MPLS WAN router
LAN 3560 switch connecting local PCs and servers
When we ping the server in DR site from Main site , we are getting 4 ping Request Timeout for every 30 minutes.
The packet flows is as below
Main sitePC-Core switch-FWSM-MPLS Router-ISP WAN cloud-DR MPLS router-DR switch-server.
I want to troubleshoot that where in the transsit path 4 icmp packet drops.In order to resolve this issue, i setup my home lab with some of L3 3550 switch and 3700 router. I want to apply debug ip packet details cmd on 3550 switch and 3700 router then monitor the packet flow between 2 pcs connected end to end. When I run the debug ip packet cmd on switch and router I can not see any console message for the packet flow transiting the device but if I ping switch or router interface then I could see the console message with d=x.x.x.x as local switch/router interface IP but not the transit traffic.
Also could you give the ASA or FWSM packet tracer feature to troubleshooting the packet flow thro the FWSM .
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...