<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Weird PIX Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/weird-pix-problem/m-p/896258#M973861</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like it might be dropping packets due to CPU overutilization due a DoS attack from someone inside spoofing those IP address of 169.254.x.x.  Have you checked the CPU when that occurs? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you had that command in there working before, then something other than configuration or hardware is triggering the packets on the inside interface to be dropped. My guess is someone is causing trouble perhaps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 14 Oct 2007 16:47:35 GMT</pubDate>
    <dc:creator>autobot130</dc:creator>
    <dc:date>2007-10-14T16:47:35Z</dc:date>
    <item>
      <title>Weird PIX Problem</title>
      <link>https://community.cisco.com/t5/network-security/weird-pix-problem/m-p/896256#M973859</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 pix firewalls in failover mode.  All of a sudden the primary started dropping all traffic on the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when doing a sh log I was seeing litterally hundreds of Deny UDP reverse path check errors on the inside interface.  the log counter was going up hundreds in seconds with these messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so I turned off the primary firewall and the standby kicked in and there are no issues at all.  as soon as you turn the primary back on same problem, all traffic on inside is dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the &lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;command turned on so its doing its job if its spoofing but why am I not seeing the same problem on the secondry firewall once that has become active?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im stumped with this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;oh yeah and the ip address source in the log message is a 169.254.127.47 so 169.254.255.255 which the last two octets in the source address changing all the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-pix-problem/m-p/896256#M973859</guid>
      <dc:creator>darkbeatzz</dc:creator>
      <dc:date>2019-03-11T11:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Weird PIX Problem</title>
      <link>https://community.cisco.com/t5/network-security/weird-pix-problem/m-p/896257#M973860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The use of a pair of identical PIX devices (model, memory, network interface cards (NICs), operating system versions), high availability can be provided with no operator intervention.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094ea7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094ea7.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2007 15:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-pix-problem/m-p/896257#M973860</guid>
      <dc:creator>vkapoor5</dc:creator>
      <dc:date>2007-10-12T15:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Weird PIX Problem</title>
      <link>https://community.cisco.com/t5/network-security/weird-pix-problem/m-p/896258#M973861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like it might be dropping packets due to CPU overutilization due a DoS attack from someone inside spoofing those IP address of 169.254.x.x.  Have you checked the CPU when that occurs? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you had that command in there working before, then something other than configuration or hardware is triggering the packets on the inside interface to be dropped. My guess is someone is causing trouble perhaps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Oct 2007 16:47:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-pix-problem/m-p/896258#M973861</guid>
      <dc:creator>autobot130</dc:creator>
      <dc:date>2007-10-14T16:47:35Z</dc:date>
    </item>
  </channel>
</rss>

