cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
718
Views
0
Helpful
1
Replies

solved

1 Accepted Solution

Accepted Solutions

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Santosh,

I do not see anything wrong on the information you have provide us, now we can see that the FWSM is replying to all the ICMP request received from the ACE, next thing to do wiill be to create a capture on the FWSM to see if is seeing the traffic go and comming or if somehow is being blocked.

So please create the following capture:

access-list TEST permit icmp host ACE host FWSM

access-list TEST permit icmp host FWSM host ACE

capture TEST access-list TEST interface  ACE-FWSM

Also please create the following capture on the FWSM

capture asp type asp-drop all

And then provide us the following outputs:

1-Show capture TEST

2-Show capture asp | include ACE

Note: On this captures you will need to use the ip address of the ACE and the FWSM)

Have a good one.

Julio!!!!

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Santosh,

I do not see anything wrong on the information you have provide us, now we can see that the FWSM is replying to all the ICMP request received from the ACE, next thing to do wiill be to create a capture on the FWSM to see if is seeing the traffic go and comming or if somehow is being blocked.

So please create the following capture:

access-list TEST permit icmp host ACE host FWSM

access-list TEST permit icmp host FWSM host ACE

capture TEST access-list TEST interface  ACE-FWSM

Also please create the following capture on the FWSM

capture asp type asp-drop all

And then provide us the following outputs:

1-Show capture TEST

2-Show capture asp | include ACE

Note: On this captures you will need to use the ip address of the ACE and the FWSM)

Have a good one.

Julio!!!!

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking products for a $25 gift card