cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
198
Views
0
Helpful
1
Replies

End-to-end PIXes / any Random Packet Sequence issues?

ppoone-systems
Level 1
Level 1

Group, soliciting war stories ...

Has anyone attempted deploying two PIXes end-to-end (in our "lab", the "outside" PIX-inside NIC crossconnected to the "inside" PIX-outside NIC)?

In your loads (in our "lab", passive ftp transfers), did you see a significant increase in packet retransmissions?

We have a theory that - with both PIXes having "fixup protocol ftp 21" enabled - the randomization of the packet sequence drifts too far for the client / servers sessions.

Wanted to see if anyone else had similiar experience / issues?

Thanks,

Christopher

1 Reply 1

ppoone-systems
Level 1
Level 1

As an update,

We opened TAC case #600973949 (thanks Ricardo! :) -- the current recommendation is to not randmomize our traffic bound by translations, see if this reduces retransmissions. An example ...

No nat (inside) 2 172.20.5.0 255.255.255.0 0 0

No nat (inside) 3 172.20.6.0 255.255.255.0 0 0

nat (inside) 2 172.20.5.0 255.255.255.0 norandomseq

nat (inside) 3 172.20.6.0 255.255.255.0 norandomseq

We have a period of windows coming up to test this. Either way the cookie crumbles, I'll report in.

Thanks,

Christopher

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card