<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 515 -- Number of connections per host? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718268#M557983</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shrikant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pix version number is 8.0(3) but I have another unit which has 8.0(4) which I will be using in this role soon. ASDM is 6.0(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does "Clear "Xlate" only clear NAT translations or all connections?&amp;nbsp; Most of my traffic is using public IP addresses and not NATted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gavin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Apr 2011 13:47:20 GMT</pubDate>
    <dc:creator>gavinfoster</dc:creator>
    <dc:date>2011-04-13T13:47:20Z</dc:date>
    <item>
      <title>Pix 515 -- Number of connections per host?</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718266#M557976</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my Pix515E ASDM console I quite often see large surges in the total number of connections. I would like to find a convenient way to see what (or who) is causing this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command Show Local gives the answers but it returns details of each connection and I can't see a way to omit the detail. Show Conn Count just gives the total. Ideally I would like to get a summary of the number of connections (TCP/UDP) for each inside host. Is this possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a related matter I have used........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;static (inside,outside) 12.34.56.00 2.34.56.00 netmask 255.255.255.0 tcp 400 100 udp 200 &lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;..........to limit the number of connections to a subnet.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;This works and I see errors in the syslog when the limit is exceeded but when I change the limits and apply the changes, the syslog errors still show the previous limit being reached. How can I make changes to these connection limits take effect (without reloading the Pix)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718266#M557976</guid>
      <dc:creator>gavinfoster</dc:creator>
      <dc:date>2019-03-11T20:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 -- Number of connections per host?</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718267#M557980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gavin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you tell us which version of PIX you are running? The later versions do have modifications to the show local-host command to filter unnecessary data. If you tell the version you are running, then i can look up what options are available to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly, I think you can run the command "clear xlate" to clear existing xlates, instead of rebooting the PIX. However, existing connections will get disconnected for a moment. So I would suggest to do this when minimal traffic is passing through the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Apr 2011 13:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718267#M557980</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-13T13:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 -- Number of connections per host?</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718268#M557983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shrikant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pix version number is 8.0(3) but I have another unit which has 8.0(4) which I will be using in this role soon. ASDM is 6.0(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does "Clear "Xlate" only clear NAT translations or all connections?&amp;nbsp; Most of my traffic is using public IP addresses and not NATted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gavin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Apr 2011 13:47:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718268#M557983</guid>
      <dc:creator>gavinfoster</dc:creator>
      <dc:date>2011-04-13T13:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 -- Number of connections per host?</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718269#M557985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gavin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An easy way to test would be to creat a connection through your pix and then run the 'clear xlate' command and see if the session drops. The short answer is no, the conns are not torn down. When you run the 'clear xlate' command existing connections stay up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After making changes to your conn or embryonic conn limits in your static, you need to clear the xlate before the changes will take effect. Note that you can also change these limits in the MPF. This is now the preferred method and it can be configured to be much more granular.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ex:&lt;/P&gt;&lt;P&gt;access-list tcp_acl permit tcp 10.1.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list tcp_acl permit tcp 10.2.2.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map tcp_class&lt;/P&gt;&lt;P&gt; match access-list tcp_acl&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class tcp_class&lt;/P&gt;&lt;P&gt;&amp;nbsp; set connection per-client-max 100 per-client-embryonic-max 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Apr 2011 16:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-number-of-connections-per-host/m-p/1718269#M557985</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-04-13T16:02:47Z</dc:date>
    </item>
  </channel>
</rss>

