<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 515 stop responding enabling logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133000#M728408</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using tcp logging?  Do a "write t" , and look for the "logging host" line. If it says tcp, then whenever the pix cannot log to the logging server, it will block connections. What are you using as a syslog server? Doing standards based UDP logging does not have this "feature"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 May 2003 15:11:21 GMT</pubDate>
    <dc:creator>mostiguy</dc:creator>
    <dc:date>2003-05-07T15:11:21Z</dc:date>
    <item>
      <title>Pix 515 stop responding enabling logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/132999#M728396</link>
      <description>&lt;P&gt;Hi everyone ! I've got a PIX 515E (ios version 6.2(2), pdm version (2.1) 32Mb ram).&lt;/P&gt;&lt;P&gt;Enabling logging and monitoring results (both from pix itself or sending to syslog server) Pix stop responding and give me some messages like:&lt;/P&gt;&lt;P&gt;PIX IS DISALLOWING CONNECTIONS. The only way to re-establish normal conditions is to disable anykind of logging and reload PIX.&lt;/P&gt;&lt;P&gt;Which kind of problem could be ? Memory lack ? Ios bug ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;Herman&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/132999#M728396</guid>
      <dc:creator>ermanno.boldi</dc:creator>
      <dc:date>2020-02-21T06:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 stop responding enabling logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133000#M728408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using tcp logging?  Do a "write t" , and look for the "logging host" line. If it says tcp, then whenever the pix cannot log to the logging server, it will block connections. What are you using as a syslog server? Doing standards based UDP logging does not have this "feature"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 May 2003 15:11:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133000#M728408</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2003-05-07T15:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 stop responding enabling logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133001#M728417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your answer. I'm using kiwi as  syslog server and i'm using a tcp logging. Do you advise me to use UDP rather than TCP ?&lt;/P&gt;&lt;P&gt;I'm not sure but I think tcp is the default type of loggin connection in PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;P&gt;erman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 May 2003 17:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133001#M728417</guid>
      <dc:creator>ermanno.boldi</dc:creator>
      <dc:date>2003-05-07T17:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 stop responding enabling logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133002#M728425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the exact same issue yesterday, with the same results. I am also running 6.22....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 May 2003 20:35:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133002#M728425</guid>
      <dc:creator>t.zelenik</dc:creator>
      <dc:date>2003-05-07T20:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 stop responding enabling logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133003#M728453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some people feel tcp logging is a bit more secure. But if you use it, you need to figure out how to keep the logging server running 24x7, or else expect these incidents. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 May 2003 22:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133003#M728453</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2003-05-07T22:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 stop responding enabling logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133004#M728467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On any version of the pix if you choose to log via TCP and the syslog server is not reachable from the pix for any reason your pix will stop passing traffic. With Kiwi choose to use UDP and you will be fine. I have had a pix logging to a Kiwi server (desktop running 2000server) for at least a year now and no issues.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2003 12:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133004#M728467</guid>
      <dc:creator>apriore685</dc:creator>
      <dc:date>2003-05-08T12:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 stop responding enabling logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133005#M728485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everybody !! Thank you very much for your support. &lt;/P&gt;&lt;P&gt;I will try to use UDP logginging and I will keep you informed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Herman&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2003 16:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133005#M728485</guid>
      <dc:creator>ermanno.boldi</dc:creator>
      <dc:date>2003-05-08T16:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515 stop responding enabling logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133006#M728501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same issue. I was going to post this exact same thing and then found this thread. I am using a PIX 515 and software v5.1(2). I have tried using a command like "logging host dmz 10.x.x.x" which should use the default of udp/514, and I too get this blocking behavior. I am using PFSS as the syslog server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First time I tried to turn on logging it was with TCP and a level of "debugging": a bad idea, which brought the PIX down. The second time, I removed the existing "logging host" command and entered a new one using the default protocol and port (i.e. I did not specify any protocol/port, so it should have defaulted to udp/514) and tried "logging trap informational" I got about 15 log messages (progress, at least!) before I tried a ping through the PIX and it again shut down, blocking out all traffic. Both times someone had to telnet from inside and reload it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that when I don't specify the protocol and port, it is actually defaulting to TCP? When I do "show logging" it does not say. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 May 2003 22:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-stop-responding-enabling-logging/m-p/133006#M728501</guid>
      <dc:creator>jmontgom61</dc:creator>
      <dc:date>2003-05-15T22:38:16Z</dc:date>
    </item>
  </channel>
</rss>

