<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix firewall blocking Internet access once in a while; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543056#M501096</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mmm  ...  perhaps you have connection limits on your nat statements. that will stop outgoing connections for the whole subnet once the limited is reached. Can you post the output of  sh run | inc nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"max_conns Specifies the maximum number of simultaneous TCP and UDP connections for&lt;/P&gt;&lt;P&gt;the entire subnet. The default is 0, which means unlimited connections. (Idle&lt;/P&gt;&lt;P&gt;connections are closed after the idle timeout specified by the timeout conn&lt;/P&gt;&lt;P&gt;command.)&lt;/P&gt;&lt;P&gt;Note This option does not apply to outside NAT. The firewall only tracks&lt;/P&gt;&lt;P&gt;connections from a higher security interface to a lower security interface.&lt;/P&gt;&lt;P&gt;If you set max_conns as well as the outside option, the max_conns option&lt;/P&gt;&lt;P&gt;is ignored. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are NOT having any connection limits then ... it sounds like your PIX could be running out of resources ... I suggest you checking that your PIX satisfies the minimum requirements for the version of OS you are running. I believe is 6.3 (3) right ..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/sw/secursw/ps2120/prod_release_note09186a0080579fd2.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/sw/secursw/ps2120/prod_release_note09186a0080579fd2.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can perform some performance analysis to find out the overall consition of your PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_tech_note09186a008009491c.shtml" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_tech_note09186a008009491c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ...  please rate it it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 May 2006 23:15:57 GMT</pubDate>
    <dc:creator>Fernando_Meza</dc:creator>
    <dc:date>2006-05-25T23:15:57Z</dc:date>
    <item>
      <title>Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543055#M501094</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a pix 515E, 3.6(3). The pix blocking a Internet access sometims. I can not ping Interfaces at blocking time. And my syslog logging shows that connection are stopped. How can I find out the resen why. To make pix work igen, I have to turn off and on igen. What is wroung? Can anybody give me some advise?  Tanks in advance!&lt;/P&gt;&lt;P&gt;Sfanayei&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sfanayei&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543055#M501094</guid>
      <dc:creator>sfanayei</dc:creator>
      <dc:date>2020-02-21T08:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543056#M501096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mmm  ...  perhaps you have connection limits on your nat statements. that will stop outgoing connections for the whole subnet once the limited is reached. Can you post the output of  sh run | inc nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"max_conns Specifies the maximum number of simultaneous TCP and UDP connections for&lt;/P&gt;&lt;P&gt;the entire subnet. The default is 0, which means unlimited connections. (Idle&lt;/P&gt;&lt;P&gt;connections are closed after the idle timeout specified by the timeout conn&lt;/P&gt;&lt;P&gt;command.)&lt;/P&gt;&lt;P&gt;Note This option does not apply to outside NAT. The firewall only tracks&lt;/P&gt;&lt;P&gt;connections from a higher security interface to a lower security interface.&lt;/P&gt;&lt;P&gt;If you set max_conns as well as the outside option, the max_conns option&lt;/P&gt;&lt;P&gt;is ignored. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are NOT having any connection limits then ... it sounds like your PIX could be running out of resources ... I suggest you checking that your PIX satisfies the minimum requirements for the version of OS you are running. I believe is 6.3 (3) right ..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/sw/secursw/ps2120/prod_release_note09186a0080579fd2.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/sw/secursw/ps2120/prod_release_note09186a0080579fd2.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can perform some performance analysis to find out the overall consition of your PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_tech_note09186a008009491c.shtml" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_tech_note09186a008009491c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ...  please rate it it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 May 2006 23:15:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543056#M501096</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-05-25T23:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543057#M501098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Tanks a lot. I will examine it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sfanayei&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2006 10:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543057#M501098</guid>
      <dc:creator>sfanayei</dc:creator>
      <dc:date>2006-05-26T10:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543058#M501099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is your license?  If your license is not unrestricted then you are probebly running out of outbound sessions and by resetting, you clear it and start over eventualy running out and then requiring a reset.  Run the PDM and it will shouw you your license and how many sessions you have open.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2006 22:06:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543058#M501099</guid>
      <dc:creator>john.king</dc:creator>
      <dc:date>2006-05-26T22:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543059#M501100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Tanks a lot for your replay. I have restricted license, but what is limits for outbound sessions numbers for a restricted license? And how can I finde out?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sfanayei&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 May 2006 17:29:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543059#M501100</guid>
      <dc:creator>sfanayei</dc:creator>
      <dc:date>2006-05-28T17:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543060#M501101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ..   maximum concurrent connections are 48.000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a00800b0d85.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a00800b0d85.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ..please rate it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2006 01:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543060#M501101</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-05-29T01:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543061#M501102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reduce the connection timeout using timeout conn command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to clear the transalations using clear xlate and clear arp  command insted of rebooting the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manoj&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2006 09:23:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543061#M501102</guid>
      <dc:creator>manoj.kv</dc:creator>
      <dc:date>2006-05-29T09:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543062#M501103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have these line in my configuration.&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;How much can I Reduce den without effecting somting els?&lt;/P&gt;&lt;P&gt;Tanks in advance&lt;/P&gt;&lt;P&gt;Sfanayei&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 May 2006 11:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543062#M501103</guid>
      <dc:creator>sfanayei</dc:creator>
      <dc:date>2006-05-30T11:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543063#M501104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Changing the xlate to 1:00:00 and conn timeout to  0:30:00 will not create any problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manoj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2006 03:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543063#M501104</guid>
      <dc:creator>manoj.kv</dc:creator>
      <dc:date>2006-06-02T03:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Pix firewall blocking Internet access once in a while;</title>
      <link>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543064#M501105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will run with this new parameters som days to see how pix will react. Tanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sfanayei&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2006 05:44:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-firewall-blocking-internet-access-once-in-a-while/m-p/543064#M501105</guid>
      <dc:creator>sfanayei</dc:creator>
      <dc:date>2006-06-06T05:44:43Z</dc:date>
    </item>
  </channel>
</rss>

