- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-27-2018 12:54 PM
01-29-2018 01:45 AM
Have you verified why the packet was in the drop stage? you can follow global counters while you're doing packetcaptures:
> show counter global filter delta yes packet-filter yes
This will show why packets may get discarded (also, traffic logs or threat logs may help shed light on what's going on)
01-29-2018 03:18 AM
01-29-2018 03:29 AM
01-29-2018 03:39 AM
can you include a network design and what your routing table looks like?
there may be overlap in your IP subnets on your interfaces, or irregularities in your routing table
01-29-2018 04:01 AM
Hi, here is the network diagram
01-29-2018 04:23 AM
that looks more straight forward than I had expected 🙂
So your firewall has 1 interface 88.200.12.2/30, one interface 81.29.27.33/27, the static routing table is 0.0.0.0/0 -> 88.200.12.1
Then a security policy any any accept, no nat ?
Ah but wait, it's the same ISR4K providing the ipsec endpoint that also provides your WAN routing ?
could it be it is performing som einternal routing and some packets may be egressing on the opposite side of the firewall ?
01-29-2018 04:38 AM
Hi, there are two different ISR routers installed.
There is not NAT configured between OUTSIDE and DMZ.
01-29-2018 06:25 AM
Any chance you're running < 8.0.7 code?
01-29-2018 06:29 AM
Hi, no, we're running 8.0.7.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!