<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 7.2(1) clear xlate issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576164#M499269</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We'll, I made the changes and added a second global PAT.  When I came to work this AM is was still slow on http connections.  I had to do a clear xlate to restore the speed.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jul 2006 12:54:03 GMT</pubDate>
    <dc:creator>happystate_2</dc:creator>
    <dc:date>2006-07-20T12:54:03Z</dc:date>
    <item>
      <title>Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576150#M499254</link>
      <description>&lt;P&gt;Every morning I have to issue a clear xlate on our firewall to browse the Internet.  Our inbound web servers are not affected.  Any ideas on getting a handle on this problem  This issue has been a tough nut to crack.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:03:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576150#M499254</guid>
      <dc:creator>happystate_2</dc:creator>
      <dc:date>2020-02-21T09:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576151#M499256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using NAT or PAT?  If you run out of address in the NAT pool you would have to clear the xlate to allow new traffic to get an IP.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jul 2006 17:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576151#M499256</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2006-07-18T17:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576152#M499257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think that run a "clear xlate" command all the days is the ideal solution&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jul 2006 19:07:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576152#M499257</guid>
      <dc:creator>josky_jara</dc:creator>
      <dc:date>2006-07-18T19:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576153#M499258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have checked every thing I can think of.  I made sure my ethernet ports were set to 100 full.  I have also replaced the actual pix hardware (same config).  Still no luck.  I am replacing my ethernet cables tonight.  I am waiting on a smartnet contract number, then I'm calling Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have downgraded from 7.X back to 6.3 same problem?  I'm I missing something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll post a sanatized config if anybody is interested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 02:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576153#M499258</guid>
      <dc:creator>happystate_2</dc:creator>
      <dc:date>2006-07-19T02:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576154#M499259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using PAT.  I am using only 1 address for outbound traffic.  I also have a restricted license.  What is the limitation of this license.  Maybe a license upgrade is needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 02:24:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576154#M499259</guid>
      <dc:creator>happystate_2</dc:creator>
      <dc:date>2006-07-19T02:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576155#M499260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How many internal hosts do you have using the PAT? Also, do you have many static's?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 02:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576155#M499260</guid>
      <dc:creator>glen.messenger</dc:creator>
      <dc:date>2006-07-19T02:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576156#M499261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should enable logging to get a better idea of what is happening.  Also, the next time the issue happens, do a "show xlate" and "show conn".  A sanitized config would help too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!  If so, please rate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 04:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576156#M499261</guid>
      <dc:creator>hemendoz</dc:creator>
      <dc:date>2006-07-19T04:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576157#M499262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;License definetely applies limitations as to thenumber of concurrent connections you can have ...  for example for a 501  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;License Function&lt;/P&gt;&lt;P&gt;10 User License Support for up to ten concurrent connections from different&lt;/P&gt;&lt;P&gt;source IP addresses on the internal network to traverse the&lt;/P&gt;&lt;P&gt;firewall. Also provides DHCP server support for up to 32 leases.&lt;/P&gt;&lt;P&gt;50 User License Support for up to 50 concurrent connections from different&lt;/P&gt;&lt;P&gt;source IP addresses on the internal network to traverse the&lt;/P&gt;&lt;P&gt;firewall. Also provides DHCP server support for up to 128&lt;/P&gt;&lt;P&gt;leases.&lt;/P&gt;&lt;P&gt;Unlimited User License Support for an unlimited number of concurrent connections from&lt;/P&gt;&lt;P&gt;different source IP addresses on the internal network to traverse&lt;/P&gt;&lt;P&gt;the firewall. Also provides DHCP server support for up to 256&lt;/P&gt;&lt;P&gt;leases.&lt;/P&gt;&lt;P&gt;DES Encryption License Support for 56-bit DES encryption.&lt;/P&gt;&lt;P&gt;3DES/AES Encryption License Support for 168-bit 3DES and up to 256-bit AES encryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ..  please rate if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 04:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576157#M499262</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-07-19T04:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576158#M499263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you had 7.0 you have at least the 515 and even with a restricted license you should be fine.  When you PAT an ip address it can handle 4024(not sure if this is the exact number) xlates.  If you have to many outbound xlates at some point it will reach the limit.  Best way to fix this is add more then 1 pat entry or us a nat pool backed up with PAT.  If you don't have any more IP's you could lower the xlate timeout value.  The default is 3 hours so by setting it lower it may help your issue.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chad   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 13:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576158#M499263</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2006-07-19T13:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576159#M499264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running 7.2(1)  I am unsure on how to do what your are describing.  I am attaching a sanatized config.  My timeout values are set to default.  We have about 300 internal hosts.  Also something in the config may be wrong  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 13:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576159#M499264</guid>
      <dc:creator>happystate_2</dc:creator>
      <dc:date>2006-07-19T13:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576160#M499265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have posted a sanatized config.  Hopefully its readable.  Just an update, we don't have trouble during the day.  It seems to happen at night.  I have to clear the translation table(clear xlate) every morning.  And it just started about 2 months ago.  This firewall has been in use for almost 2 years.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 14:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576160#M499265</guid>
      <dc:creator>happystate_2</dc:creator>
      <dc:date>2006-07-19T14:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576161#M499266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your config is fine.  But your trying to PAT 300 hosts to 1 ip.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This link should help.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_guide_chapter09186a008063b1fa.html" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_guide_chapter09186a008063b1fa.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;PAT&lt;/P&gt;&lt;P&gt;Global (outside) 1 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Multiple PAT&lt;/P&gt;&lt;P&gt;Global (outside) 1 192.168.1.1&lt;/P&gt;&lt;P&gt;Global (outside) 1 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT pool with PAT backup&lt;/P&gt;&lt;P&gt;Global (outside) 1 192.168.1.1-192.168.1.100&lt;/P&gt;&lt;P&gt;Global (outside) 1 192.168.1.101&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 14:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576161#M499266</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2006-07-19T14:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576162#M499267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm assuming for multiple PAT I can place another outside IP address as the second entry.  Your example show the same IP twice.  I am going to read through the link you provided.  If I can clarify what I need, I'll make the change tonight and see what happens&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 14:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576162#M499267</guid>
      <dc:creator>happystate_2</dc:creator>
      <dc:date>2006-07-19T14:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576163#M499268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you would use another usable IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the typo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2006 15:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576163#M499268</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2006-07-19T15:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576164#M499269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We'll, I made the changes and added a second global PAT.  When I came to work this AM is was still slow on http connections.  I had to do a clear xlate to restore the speed.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jul 2006 12:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576164#M499269</guid>
      <dc:creator>happystate_2</dc:creator>
      <dc:date>2006-07-20T12:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 7.2(1) clear xlate issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576165#M499270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Turn on logging and look for errors when you are having the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The error below would indicate the xlate pool has been exhausted.     &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log Message %PIX-3-202001: Out of address translation slots!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Action:&lt;/P&gt;&lt;P&gt;Add more PAT addresses.  Alternatively, shorten the timeout for xlate and conn. This could also be caused by insufficient memory; reduce the amount of memory usage, or purchase additional memory. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jul 2006 14:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-2-1-clear-xlate-issue/m-p/576165#M499270</guid>
      <dc:creator>cpembleton</dc:creator>
      <dc:date>2006-07-20T14:07:49Z</dc:date>
    </item>
  </channel>
</rss>

