Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Upgrade from 12.4 to 12.4T, ios firewall not working?

Hi,

I'm attempting an upgrade from 12.4-18 to latest 12.4-24T on a 1841 (my point for upgrade is to allow TCP out of order segments through the firewall which seems to have been introduce in 12.4-11T).

The router uses NAT, and a PPP dialer for an ATM (adsl) interface. Its initial configuration was done by SDM, so it has the default SDM low firewall configuration.

When upgrading to 12.4-24T, all the traffic that is not explicitely permitted by the inbound access list of the outside dialer 0 interface is blocked by it, even though a show ip ips inspect all shows all the traffic accepted by the firewall.

It all looks like that the access-lists exceptions were not added in front of my inbound access-lists as it should have been done.

I can post the configuration if needed.

Any ideas on how I can debug this issue?

2 REPLIES

Re: Upgrade from 12.4 to 12.4T, ios firewall not working?

Check the bug toolkit-

http://www.cisco.com/cgi-bin/Support/Bugtool/launch_bugtool.pl

We ran into something like this and it was a bug. I don't remember the IOS versions though.

New Member

Re: Upgrade from 12.4 to 12.4T, ios firewall not working?

Hi,

Thanks for your answer.

Although I couldn't find the issue witht bug toolkit, I upgraded to an older version 12.4-15T8 and it seems to work fine so far, so I think the issue appearead in a subsequent release.

Thanks,

115
Views
0
Helpful
2
Replies