<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515 hangs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380546#M549878</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You might be refering to the following Field Notice:&lt;/P&gt;&lt;P&gt;-- Field Notice: PIX 515 and 506 Hang:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_field_notice09186a00800949c7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_field_notice09186a00800949c7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem has been resolved on the production line and units manufactured as of October, 2001 does not present this problem (traffic related!).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, please note that the FN applies to PIX-515, and not to PIX-515Es... If your PIX is hanging every two weeks or so, how do you resolve the problem? I guess that simply by re-loading it, right? When it does hang, do you have console access to it? If you do, could you enter the commands "clear xlate" and "clear local-host", and see if traffic resumes? Before doing so, capture a 'show tech' from the PIX (I'm wondering if the PIX memory is just filled out!).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico Rodriguez&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 02 Apr 2005 00:57:49 GMT</pubDate>
    <dc:creator>fedrodri</dc:creator>
    <dc:date>2005-04-02T00:57:49Z</dc:date>
    <item>
      <title>PIX 515 hangs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380545#M549877</link>
      <description>&lt;P&gt;I have a 515E firewall that about every two weeks just hangs. I heard through our T-1 provider that there was a field notice or recall out on this issue, but can't find anything that is later than May 2002. Is there something newer to review?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:02:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380545#M549877</guid>
      <dc:creator>malcorn</dc:creator>
      <dc:date>2020-02-21T08:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 hangs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380546#M549878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You might be refering to the following Field Notice:&lt;/P&gt;&lt;P&gt;-- Field Notice: PIX 515 and 506 Hang:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_field_notice09186a00800949c7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_field_notice09186a00800949c7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem has been resolved on the production line and units manufactured as of October, 2001 does not present this problem (traffic related!).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, please note that the FN applies to PIX-515, and not to PIX-515Es... If your PIX is hanging every two weeks or so, how do you resolve the problem? I guess that simply by re-loading it, right? When it does hang, do you have console access to it? If you do, could you enter the commands "clear xlate" and "clear local-host", and see if traffic resumes? Before doing so, capture a 'show tech' from the PIX (I'm wondering if the PIX memory is just filled out!).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico Rodriguez&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Apr 2005 00:57:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380546#M549878</guid>
      <dc:creator>fedrodri</dc:creator>
      <dc:date>2005-04-02T00:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 hangs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380547#M549879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have verified that the PIX 515E is not related to the field notice. When it does hang, there is no access except for rebooting since I am not at the location. It is sitting in a co-lo environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is a sample of the "show tech"while PIX is OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   PIX-515E, 32 MB RAM, CPU Pentium II 433 MHz&lt;/P&gt;&lt;P&gt;Flash E28F128J3 @ 0x300, 16MB&lt;/P&gt;&lt;P&gt;BIOS Flash AM29F400B @ 0xfffd8000, 32KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0: ethernet0: address is 000c.ce7d.698d, irq 10&lt;/P&gt;&lt;P&gt;1: ethernet1: address is 000c.ce7d.698e, irq 11&lt;/P&gt;&lt;P&gt;2: ethernet2: address is 0002.b3cd.98f1, irq 11&lt;/P&gt;&lt;P&gt;Licensed Features:&lt;/P&gt;&lt;P&gt;Failover:                    Disabled&lt;/P&gt;&lt;P&gt;VPN-DES:                     Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES:                Disabled&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces: 3&lt;/P&gt;&lt;P&gt;Maximum Interfaces:          5&lt;/P&gt;&lt;P&gt;Cut-through Proxy:           Enabled&lt;/P&gt;&lt;P&gt;Guards:                      Enabled&lt;/P&gt;&lt;P&gt;URL-filtering:               Enabled&lt;/P&gt;&lt;P&gt;Inside Hosts:                Unlimited&lt;/P&gt;&lt;P&gt;Throughput:                  Unlimited&lt;/P&gt;&lt;P&gt;IKE peers:                   Unlimited&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;This PIX has a Restricted (R) license.&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;Serial Number: 807182641 (0x301ca131)&lt;/P&gt;&lt;P&gt;Running Activation Key: &lt;/P&gt;&lt;P&gt;Configuration last modified by enable_15 at 21:13:26.738 UTC Fri Apr 1 2005&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;------------------ show clock ------------------&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;21:15:23.710 UTC Fri Apr 1 2005&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;------------------ show memory ------------------&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;Free memory:        14753664 bytes&lt;/P&gt;&lt;P&gt;Used memory:        18800768 bytes&lt;/P&gt;&lt;P&gt;-------------     ----------------&lt;/P&gt;&lt;P&gt;Total memory:       33554432 bytes&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;------------------ show conn count ------------------&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;79 in use, 3638 most used&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;------------------ show xlate count ------------------&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;78 in use, 675 most used&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;------------------ show blocks ------------------&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;  SIZE    MAX    LOW    CNT&lt;/P&gt;&lt;P&gt;     4   1600   1596   1599&lt;/P&gt;&lt;P&gt;    80    400    397    400&lt;/P&gt;&lt;P&gt;   256   2036   1708   2036&lt;/P&gt;&lt;P&gt;  1550   1189    620    695&lt;/P&gt;&lt;P&gt;  2560    200    193    198&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;------------------ show interface ------------------&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Apr 2005 01:10:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380547#M549879</guid>
      <dc:creator>malcorn</dc:creator>
      <dc:date>2005-04-02T01:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 hangs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380548#M549880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It would have been nice to get a 'show tech' from when the PIX hangs; what is the version that you're running; it was cut-off from the 'show tech' you sent... Now, what about if you do a 'show local-host'? What I would be looking for is for unusual entries on this table (it holds both xlate and conn table, on a per host basis), like per example connections or xlates that have been idle for more time than what you have specified on the 'timeout xlate' and 'timeout conn'... I have a hintch it is an xlate/conn related problem, and not with your box (more like a sofware bug)...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the hangs related to certain heavy traffic conditions? Keep monitoring the 1550 blocks (see if they reach 0); those memory blocks are for Ethernet packets storage before sending them to the PIX OS for processing! It's bad if they reach zero :0(, or could be that you're PIX is overwhelmed with traffic!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps! And definitely, try getting console access when the problem happens and capture a 'show tech' and 'show local-host'; this will help a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico Rodriguez&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Apr 2005 01:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380548#M549880</guid>
      <dc:creator>fedrodri</dc:creator>
      <dc:date>2005-04-02T01:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 hangs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380549#M549881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PIX version 6.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only problem is that something on my network is using an old set of IP addresses that we used from a previous ISP 209.152.196.0/128&lt;/P&gt;&lt;P&gt;These were some printers:&lt;/P&gt;&lt;P&gt;local host: &amp;lt;192.168.10.61&amp;gt;,&lt;/P&gt;&lt;P&gt;    TCP connection count/limit = 0/unlimited&lt;/P&gt;&lt;P&gt;    TCP embryonic count = 0&lt;/P&gt;&lt;P&gt;    TCP intercept watermark = unlimited&lt;/P&gt;&lt;P&gt;    UDP connection count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;  AAA:        &lt;/P&gt;&lt;P&gt;  Xlate(s):   &lt;/P&gt;&lt;P&gt;    Global 146.145.??.?? Local 192.168.10.61&lt;/P&gt;&lt;P&gt;  Conn(s):    &lt;/P&gt;&lt;P&gt;    UDP out 209.152.196.30:161 in 192.168.10.61:1032 idle 0:01:41 flags -&lt;/P&gt;&lt;P&gt;              &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Apr 2005 03:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380549#M549881</guid>
      <dc:creator>malcorn</dc:creator>
      <dc:date>2005-04-02T03:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 hangs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380550#M549882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would seem that printer is communicating with that outside host via SNMP... but, the translation is made correctly; it is not being translated to something on the old IP address space given by the previous ISP... So this 'local-host' entry seems to be fine! Are there any local hosts being translated to something on the old IP address space?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that 146.145.x.x an IP address from a global Pool? Have you verify that you have at least one PAT address for once the global pool is exhausted? Could you confirm whether all traffic stops or if it is only for certain hosts that inbound/outbound traffic will not work? When the PIX hangs, I mean... Then PIX 6.3.? is the version? I was thinking of this bug, perhaps (?):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- CSCdy58717 Bug Details: xlate table does not timeout entries.Need clear xlate to work:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCdy58717" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCdy58717&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've seen some behaviors similar to this on version 6.3.1, or look into this one (it could eventually fill out the memory if the DNS connections are not cleared):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- CSCec45748 Bug Details: New DNS conns reset the idle timer of previous DNS conns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far, this is all that I can tell you. There is not enough information to tell exactly what's going on. You may want to open a TAC case as well, but you're gonna be asked for the same information: show tech from the time the problem happens and other things! See if you have anything saved in flash: 'show crashinfo', there might be something there that could help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico Rodriguez&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Apr 2005 02:03:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380550#M549882</guid>
      <dc:creator>fedrodri</dc:creator>
      <dc:date>2005-04-03T02:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 hangs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380551#M549883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried to get to both of the bug details, but the links don't work. I am attaching a crashinfo to this message. Maybe this will help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Apr 2005 13:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380551#M549883</guid>
      <dc:creator>malcorn</dc:creator>
      <dc:date>2005-04-03T13:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 hangs</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380552#M549884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi! Thanks for the information... I'm looking at it and let you know as soon as I know...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico Rodriguez&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2005 16:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-hangs/m-p/380552#M549884</guid>
      <dc:creator>fedrodri</dc:creator>
      <dc:date>2005-04-04T16:49:43Z</dc:date>
    </item>
  </channel>
</rss>

