cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
743
Views
0
Helpful
5
Replies

pix 525 cluster failover

hi guys,  a customer have 2 pix 525 with ver 7.0.1 in a failover configuration with serial cable and 2 sc fiber interface and 2 fastethernet 1 used for failover.

the strange behaviour is that when i try to do traffic from inside to dmz or dmz to inside the maximum transfer is 862Kb/s to 1MB/s not more.... i don't understand what's happened...

the show mem and show cpu are normal 7% mem used and 1-2% cpu used. attached you will find the configuration.

pls advice

5 Replies 5

Maykol Rojas
Cisco Employee
Cisco Employee

Hi,

Does it happen if you do a failover to the other unit? With what kind of traffic are you testing this with? Can you take a capture on Inside and DMZ traffic?

Let us know.

Mike Rojas

Security Technical Lead

Mike

hi Mike thanks for reply,

it happens not when i do failover but on master firewall with all 2 pix on. i can capture the traffic on inside and dmz interface, if you can tell me how i can execute this traffic capture i will post you the result immediately.

BR

Giulio

Here it is:

******* Capture configuration ******

{Enable GUI interface:}

http 0 0 inside

http server enable

{For outside interface:}

access-list capture1 permit ip host   host

access-list capture1 permit ip host host

{For inside interface:}

access-list capture2 permit ip host host

access-list capture2 permit ip host host

capture tcpin access-list capture1 interface outside

capture tcpout access-list capture2 interface inside

****** To download the files then… *****

Open the browser

https:///capture/tcpin/pcap

https:///capture/tcpout/pcap

Note:

Username: blank = no name

Password: {enable password}

********* To delete them *********

clear access-list capture1

clear access-list capture2

no capture tcpin

no capture tcpout

********** End *********

Mike

Mike

hi Mike,

i have initiated a netbios transfer from 10.1.1.16 to 172.16.10.30 and with 1Gb/s connection the file transfer has gone with no more than 1Mbit/s

attached you will find the capture.

Thanks again

Giulio

hi any news?? please advice

thanks

Review Cisco Networking for a $25 gift card