<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix crashing with no crashinfo file in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-crashing-with-no-crashinfo-file/m-p/1296903#M780320</link>
    <description>&lt;P&gt;I have this problem that I am hoping someone can help me with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix 515 (R) with 64M RAM and 16MF running 7.2(3).  I have outside and inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration is very simple I have a Linux host behind inside interface with &lt;/P&gt;&lt;P&gt;an IP address of 192.168.6.10/24 and be NAT'ed as follows: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 4.2.2.2 192.168.6.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have web server on the outside interface with an IP address of 4.2.2.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inside interface IP address:  192.168.6.1/24&lt;/P&gt;&lt;P&gt;outside interface IP address: 4.2.2.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Linux host, I run a program called "nkiller2" that can generate thousands &lt;/P&gt;&lt;P&gt;thousands of http connections to hit the web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I start this program, I send about 20,000 http connections through the Pix515.&lt;/P&gt;&lt;P&gt;Using "show conn count", I saw that when the connection reaches about 10,000 connections,&lt;/P&gt;&lt;P&gt;the firewall goes into reboot.  After the reboot, there is NO crashinfo in the flash &lt;/P&gt;&lt;P&gt;(verified with show flash:).  In the flash, I have nothing except pix723.bin file so there&lt;/P&gt;&lt;P&gt;are plenty of spaces on the flash for crashinfo file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue with this Pix is that I can NOT upgrade to version 8.0(4) or download to 7.0(8)&lt;/P&gt;&lt;P&gt;because the pix will reboot everything 5 minutes.  With version 7.2(3), it is stable until&lt;/P&gt;&lt;P&gt;the connection goes over 10k connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen this before?  Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:24:10 GMT</pubDate>
    <dc:creator>cisco24x7</dc:creator>
    <dc:date>2019-03-11T16:24:10Z</dc:date>
    <item>
      <title>Pix crashing with no crashinfo file</title>
      <link>https://community.cisco.com/t5/network-security/pix-crashing-with-no-crashinfo-file/m-p/1296903#M780320</link>
      <description>&lt;P&gt;I have this problem that I am hoping someone can help me with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix 515 (R) with 64M RAM and 16MF running 7.2(3).  I have outside and inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration is very simple I have a Linux host behind inside interface with &lt;/P&gt;&lt;P&gt;an IP address of 192.168.6.10/24 and be NAT'ed as follows: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 4.2.2.2 192.168.6.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have web server on the outside interface with an IP address of 4.2.2.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inside interface IP address:  192.168.6.1/24&lt;/P&gt;&lt;P&gt;outside interface IP address: 4.2.2.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Linux host, I run a program called "nkiller2" that can generate thousands &lt;/P&gt;&lt;P&gt;thousands of http connections to hit the web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I start this program, I send about 20,000 http connections through the Pix515.&lt;/P&gt;&lt;P&gt;Using "show conn count", I saw that when the connection reaches about 10,000 connections,&lt;/P&gt;&lt;P&gt;the firewall goes into reboot.  After the reboot, there is NO crashinfo in the flash &lt;/P&gt;&lt;P&gt;(verified with show flash:).  In the flash, I have nothing except pix723.bin file so there&lt;/P&gt;&lt;P&gt;are plenty of spaces on the flash for crashinfo file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue with this Pix is that I can NOT upgrade to version 8.0(4) or download to 7.0(8)&lt;/P&gt;&lt;P&gt;because the pix will reboot everything 5 minutes.  With version 7.2(3), it is stable until&lt;/P&gt;&lt;P&gt;the connection goes over 10k connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen this before?  Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-crashing-with-no-crashinfo-file/m-p/1296903#M780320</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2019-03-11T16:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Pix crashing with no crashinfo file</title>
      <link>https://community.cisco.com/t5/network-security/pix-crashing-with-no-crashinfo-file/m-p/1296904#M780333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you issue "sh crash"? If there is no crash file found, then you need to connect the console and watch what the console prints.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what does "sh run logg" say? Do you have console logging enabled may be debug level. If so pls. disable that. How about http inspection is that enabled? If the connections do get established then, inspection will kick in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggest that you open a TAC case and work with an engineer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Oct 2009 23:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-crashing-with-no-crashinfo-file/m-p/1296904#M780333</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-10-07T23:06:48Z</dc:date>
    </item>
  </channel>
</rss>

