cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
785
Views
0
Helpful
7
Replies

License in PIX 501

s_palazzo
Level 1
Level 1

Hello,

I installed a syslog server in a PIX 501 , and I am having this messages.

%PIX-4-407001: Deny traffic for local-host inside:xxx.xxx.xxx.xxx, license limit of 50 exceeded

The PIX 501 has 50 user license.

And we have 7 terminals ( 7 users ) using the LAN and Internet.

I have setup the timeout xlate = 1 minute, but still have this error.

Anyone knows what is happening ?

Thanks

Santiago

7 Replies 7

luke.redd
Level 1
Level 1

Sounds like there may be a problem with your ARP tables. Everything on a network within the subnet of the Pix has the capablility of taking a license. Cisco bases your licenses based on MAC addresses that are stored in the ARP table. Its also possible that they may be corrupt for some reason.

From configuration mode, I would try this.

1. Issue "clear arp"

2. Issue "arp timeout ""seconds""

Try setting the "seconds" to something like 3600(1 hour) and see if this solves your problem.

Check the release notes of your FOS version, might be a bug?

For example: FOS 6.1.3 had

BugID CSCdw25026

License not released after 30 seconds in certain scenario.

sincerely

Patrick

I just wanted to jump in on the above post by luke.redd. This is not correct. The 501 license is based on "local-host" entries and not ARP entries. ARP entries have nothing to do with the 501 licensing scheme. You can issue a 'sh local-host' on the PIX to see the total number of licenses the PIX has counted.

As Patrick mentioned, this could be a bug in the PIX code. Can you tell us what version you have on your PIX?

Scott

Scott,

Please forgive my error, I thought I had read once that the Pix based it on ARP entries. Thank you for your input and correcting my error.

Luke

No sweat...I just wanted to correct your post for posterity sake more than anything else. I am sure you know how this information can spiral out of control.

Scott

That's very true.

Thanks again,

Luke

Hi Scoclayton,

The PIX version = 6.3(3)

Has 50 user license.

Thanks for your replay.

Santiago

Review Cisco Networking for a $25 gift card