Thursday, June 14, 2018

Difficult Problem on Firepower 4150

I'm trying to troubleshoot a problem where a database server is failing to send transaction logs from one server to another. Basically two devices were connected to a 5580 on different interfaces, and permitted to speak to each other with relevant rules. I've replaced this 5580 with a 4150 pair, and the only issue I've run into is that some transaction logs are not being sent between those two servers. To try and isolate the issue, I temporarily put a permit any [interfaces] any [src] any [dst] everywhere. However the 4150 STILL shows that the packets are being blocked in the connection events log for tcp 1521 between the two servers. I can't get my head around this, how can anything be blocked if my first rule in the list is permit any any. Can someone try explain me how that is even possible?

PS: There is absolutely no asymmetric routing going off here.



No comments:

Post a Comment