<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco PIX 501 PROBLEM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586580#M501525</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have one Cisco PIX 501 connect by outside interface to a Telecom Router. This Router show his state by web page. The router automatically each 5 minutes updates his tables and publish IP Addresses of each host connected, on his web page.&lt;/P&gt;&lt;P&gt;I think that Router capture IP Adresses of any host connect, by sending Gratuitous Arp. When this happens, my PIX 501 outside interface  becomes not operational however its state is UP - UP.&lt;/P&gt;&lt;P&gt;It seams doesn't work to Router's IP only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this situation internet results unrechable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cane anyone help me???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my Pix configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;enable password xxxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;hostname xxx&lt;/P&gt;&lt;P&gt;domain-name intranet.kkk.com&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list outside permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 10.0.0.253 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.x.x.x.0.254 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:53:53 GMT</pubDate>
    <dc:creator>sgozio</dc:creator>
    <dc:date>2020-02-21T08:53:53Z</dc:date>
    <item>
      <title>Cisco PIX 501 PROBLEM</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586580#M501525</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have one Cisco PIX 501 connect by outside interface to a Telecom Router. This Router show his state by web page. The router automatically each 5 minutes updates his tables and publish IP Addresses of each host connected, on his web page.&lt;/P&gt;&lt;P&gt;I think that Router capture IP Adresses of any host connect, by sending Gratuitous Arp. When this happens, my PIX 501 outside interface  becomes not operational however its state is UP - UP.&lt;/P&gt;&lt;P&gt;It seams doesn't work to Router's IP only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this situation internet results unrechable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cane anyone help me???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my Pix configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;enable password xxxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;hostname xxx&lt;/P&gt;&lt;P&gt;domain-name intranet.kkk.com&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list outside permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 10.0.0.253 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.x.x.x.0.254 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586580#M501525</guid>
      <dc:creator>sgozio</dc:creator>
      <dc:date>2020-02-21T08:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 PROBLEM</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586581#M501526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt;It seems like you are having a conectivity issue.&lt;/P&gt;&lt;P&gt;If you are suspicious about your provider link then you will have to capture all the information and events you can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.- Start by testing your inside network , enable icmp on the inside interface of the pix&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf term&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then , from a host at your inside network do a ping to the PIX inside IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping -t 192.168.1.254 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.- Test and check the connectivity to your router from an inside workstation , by pinging continuosly to 10.0.0.254 which is your default ip address with a   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping -t 10.0.0.254 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then , see how it goes , packet loss , variable response time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.- You can also enable your pix log , telnet to your pix and go into configuration mode and type :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf term&lt;/P&gt;&lt;P&gt;telnet timeout 60&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logg mon 7 &lt;/P&gt;&lt;P&gt;! this command will log all events to your teminal telnet or ssh session&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;term mon&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logg buff 7&lt;/P&gt;&lt;P&gt;!this command will log all avents to buffer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logg on&lt;/P&gt;&lt;P&gt;!will start logging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to capture the log events at the moment you loose conectivity to correlate any possible event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps ... !&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 May 2006 14:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586581#M501526</guid>
      <dc:creator>federico_caminos</dc:creator>
      <dc:date>2006-05-12T14:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 PROBLEM</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586582#M501527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, tks for answer!&lt;/P&gt;&lt;P&gt;1) The problem is between router and PIX, it happen also when inside interface is down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) I test by ping (I'm connect to PIX by his serial interface to my PPC) connection between router and pix. On my PPC I have also open Internet Explorer on Router Web Page, when I refresh this page the Router update connected Host IP Address list in this moment it is systematic: connection loose.&lt;/P&gt;&lt;P&gt;3) I also enable pix log but last log information is ping to router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks for your time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 May 2006 15:12:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586582#M501527</guid>
      <dc:creator>sgozio</dc:creator>
      <dc:date>2006-05-12T15:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 PROBLEM</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586583#M501528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me ask you a couple of questions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What type of router is it ? Is it a DSL router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you the administrator of the router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is DHCP configured on the router ? enabled ? disabled ? (it should be disabled on the interface connected to your PIX)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you checked speed and duplex ¿? (try fixing it to 10 full on the router and on the outside interface of the PIX)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case it seems like this is a conectivity issue not a malfunctioning PIX or a configuration related problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 May 2006 15:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586583#M501528</guid>
      <dc:creator>federico_caminos</dc:creator>
      <dc:date>2006-05-12T15:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 PROBLEM</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586584#M501529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico, tks for answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router is DSL Router, I'm Administrator of Router but it is a Italian Telecom "Black Box".&lt;/P&gt;&lt;P&gt;On Router I can configure basic parameters by web interface only.&lt;/P&gt;&lt;P&gt;DHCP is disabled.&lt;/P&gt;&lt;P&gt;I already Fix speed of PIX to 10full, on Router it is impossible to fix (It is autosensing)&lt;/P&gt;&lt;P&gt;Telecom have already change Router and I already have change PIX but the problem is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps the isuue is the Router IP discovering mechanism. In fact when I refresh router webpage were router listing inside IP connection, connection lost. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other idea???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 May 2006 08:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586584#M501529</guid>
      <dc:creator>sgozio</dc:creator>
      <dc:date>2006-05-14T08:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco PIX 501 PROBLEM</title>
      <link>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586585#M501530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seams possible problem related to Router ARP Sending, in fact by Frame capture I find this information inside Router ARP frame informations:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sender IP Address: 0.0.0.0 (0.0.0.0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Pix doesn't show anything inside log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 May 2006 15:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-pix-501-problem/m-p/586585#M501530</guid>
      <dc:creator>sgozio</dc:creator>
      <dc:date>2006-05-17T15:28:24Z</dc:date>
    </item>
  </channel>
</rss>

