<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 515 strange case in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-strange-case/m-p/596878#M527333</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have one pix 515E and is having a wried problem in it. We have a machine which connects through this pix to establish a VPN tunnel using a VPN Client S/W to a another company VPN Concentrator, The problem comes after 8 hours of consistent connectivity that the vpn client S/W drops the connection and we have to reconnect it, according to this company there VPN concentrator renews the IP address lease after 8 hours and most probably our PIX drops the connection and VPN tunnel disconnects. the difficult part in all this is that i installed the syslog and tried to find any abnormal behaviour for this problem, but nothing which would relate or help me to diagnous this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;our senario is like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have one leased line from the ISP which is terminated on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have group of IPs alloted by ISP to use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a static translation between this VPN machine IP to one outside IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have access-lists allowing specific ports and protocols for this VPN client machine for both interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have isakmp nat-traversal enable on the PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the timeout values are as following. (default)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one important thing, if i connect the VPN tunnels without bringing the PIX in between connection, it does not disconnects and that is the reason i know it's the pix which is at some point making all the problem.. and yes there is no autodisconnection feature of this VPN client S/W&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:43:20 GMT</pubDate>
    <dc:creator>silverfoxx</dc:creator>
    <dc:date>2020-02-21T08:43:20Z</dc:date>
    <item>
      <title>PIX 515 strange case</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-strange-case/m-p/596878#M527333</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have one pix 515E and is having a wried problem in it. We have a machine which connects through this pix to establish a VPN tunnel using a VPN Client S/W to a another company VPN Concentrator, The problem comes after 8 hours of consistent connectivity that the vpn client S/W drops the connection and we have to reconnect it, according to this company there VPN concentrator renews the IP address lease after 8 hours and most probably our PIX drops the connection and VPN tunnel disconnects. the difficult part in all this is that i installed the syslog and tried to find any abnormal behaviour for this problem, but nothing which would relate or help me to diagnous this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;our senario is like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have one leased line from the ISP which is terminated on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have group of IPs alloted by ISP to use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a static translation between this VPN machine IP to one outside IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have access-lists allowing specific ports and protocols for this VPN client machine for both interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have isakmp nat-traversal enable on the PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the timeout values are as following. (default)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one important thing, if i connect the VPN tunnels without bringing the PIX in between connection, it does not disconnects and that is the reason i know it's the pix which is at some point making all the problem.. and yes there is no autodisconnection feature of this VPN client S/W&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-strange-case/m-p/596878#M527333</guid>
      <dc:creator>silverfoxx</dc:creator>
      <dc:date>2020-02-21T08:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 strange case</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-strange-case/m-p/596879#M527334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just want to thank you to everyone, just wanted to share that the problem is diagnosed and it has nothing to do with PIX or it's configuration, it is related to windows 2000 operating system. if anyone ever come across this issue kindly follow the link below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://support.microsoft.com/default.aspx?scid=kb;en-us;818043" target="_blank"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;818043&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Feb 2006 09:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-strange-case/m-p/596879#M527334</guid>
      <dc:creator>silverfoxx</dc:creator>
      <dc:date>2006-02-23T09:40:43Z</dc:date>
    </item>
  </channel>
</rss>

