Firewall Issue

Hi Experts !!!

We have two firewall fwsm modules deployed on two different 6509 chassis at two different sites, connected via layer 2 link, as primary and standby modules.

NATng is enabled on the primary firewall module and all xlate and conns are getting replication to standby module.

Yesterday, suddenly NAT engine in the primary fwsm module stopped working and no inboun/outbound traffic was being passed. No changes were made.

Any ideas, what could be the issue and how it can be fixed? FWSM ver is 3.1(1)


Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

vbongaralaAuthor Commented:
Plz provide elaborate steps to fix the issue, instead of brief.
have you done a show log or show tech? I would do a show log and see if you find an answer tere as to what might have happen. Also I would do a sow tech and enter the output on the ouput interpreter tool on Cisco's website. This might give you a good idea of what's happened and what to do to address the issue.
vbongaralaAuthor Commented:
I did, show logging but did not find anything unusual but did not do show tech.

What does 'show tech' cmd do and does it provide insight into what happened and what caused the issue, that cannot be known from other show cmds ?

It is a combination of several show commands (see list below). This is the command I am normally asked by Cisco tech support when troubleshooting an issue with them. What I would do is log the session, then run the command. Save the output as a log file. Go to and upload the file you just saved. It will analyze it for you and give you recommendations and show you issues based on the analysis.

The output of the show tech-support command can include the output of the following commands:

•show apollo traffic

•show appletalk traffic

•show bootflash

•show bootvar

•show buffers

•show cdp neighbors

•show cef

•show clns traffic

•show context

•show controllers

•show decnet traffic

•show interfaces

•show ip cef

•show ip interface

•show ip traffic

•show isis

•show mpls

•show novell traffic

•show processes cpu

•show processes memory

•show running-config

•show stacks

•show version

•show vines traffic

•show xns traffic

•show file systems

•dir nvram:

•show disk0: all

•show process cpu

•show pci controller

vbongaralaAuthor Commented:
We rebooted the fwsm module and issue got fixed but i'm not quite satisfied as i really still do not know what caused it.

Do you see any other angle to the issue ?


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.