cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
268
Views
0
Helpful
1
Replies

End-to-end PIXes / any Random Packet Sequence issues?

ppoone-systems
Level 1
Level 1

Group, soliciting war stories ...

Has anyone attempted deploying two PIXes end-to-end (in our "lab", the "outside" PIX-inside NIC crossconnected to the "inside" PIX-outside NIC)?

In your loads (in our "lab", passive ftp transfers), did you see a significant increase in packet retransmissions?

We have a theory that - with both PIXes having "fixup protocol ftp 21" enabled - the randomization of the packet sequence drifts too far for the client / servers sessions.

Wanted to see if anyone else had similiar experience / issues?

Thanks,

Christopher

1 Reply 1

ppoone-systems
Level 1
Level 1

As an update,

We opened TAC case #600973949 (thanks Ricardo! :) -- the current recommendation is to not randmomize our traffic bound by translations, see if this reduces retransmissions. An example ...

No nat (inside) 2 172.20.5.0 255.255.255.0 0 0

No nat (inside) 3 172.20.6.0 255.255.255.0 0 0

nat (inside) 2 172.20.5.0 255.255.255.0 norandomseq

nat (inside) 3 172.20.6.0 255.255.255.0 norandomseq

We have a period of windows coming up to test this. Either way the cookie crumbles, I'll report in.

Thanks,

Christopher

Review Cisco Networking for a $25 gift card