12-27-2004 07:49 AM - edited 02-20-2020 11:49 PM
Hi,
I have Cisco PIX 515-E-UR with 6 interfaces. DMZ2 some times its working and sometimes not. I used PDM to see the status interface and showed as DOWN. Can anybody help me how to troubleshoot this issue. Is there any hardware problem?
12-27-2004 08:50 AM
Hi, I have couple of questions from you:
1) Is the Pix-515E in failover ?
2) Do you have a switch connected to DMZ2 and if so then make sure you have hardcode the speed of the DMZ2 interface as well as that of the directly connected switch.
3) show interface DMZ2
Does the above command show you any errors on the interface... specially and CRC or deferred errors? And if so then try changing the cables.
4) What is the security level of DMZ2 interface? Make sure that is should not be same as that of any other interface.
5) If possible, could you upload the output of "show tech" from the Pix?
Regards,
Rahul Pathania.
12-28-2004 06:05 AM
Yes Rahul,
I found lots of CRC and Interface Packet Errors. I saw there is a huge Input Errors (360) CRC (200) Deferred (2). I changed the cable but still it shows the same. I configured the interface speed to 10half as well.Do you think is there any problem with Port or Firewall?
12-28-2004 07:12 AM
That sounds like DUPLEX MODE errors.
You have two choices to fix that:
1.) Set Duplex on both the PIX and the Switch to the same duplex mode. Lets say 100MB Full Duplex.
2.) Set both to Auto negotiation.
sincerely
Patrick
12-28-2004 09:48 AM
Hi Shabier,
CRC errors refer to cabling issue and input erros refer to interface speed mismatch due to which you would see deferred packets as well.
There should not be any issues with the port on the firewall however i woudl recommend you to chenge the speed of the interface to:
either
interface DMZ2 auto
or to
interface DMZ2 100full
and then give the command:
clear interface
this would reset the interface counters to 0 so you may monitor the errors on the interface after making the changes.
12-28-2004 09:48 AM
Hi Shabier,
CRC errors refer to cabling issue and input erros refer to interface speed mismatch due to which you would see deferred packets as well.
There should not be any issues with the port on the firewall however i woudl recommend you to chenge the speed of the interface to:
either
interface DMZ2 auto
or to
interface DMZ2 100full
and then give the command:
clear interface
this would reset the interface counters to 0 so you may monitor the errors on the interface after making the changes.
12-29-2004 04:41 AM
Hi Rohit,
This option i tried long back like changing the cable and setting the speed of the interface to 10full (half as well). But still the problem exists. I wonder where if i get any hint to troubleshoot. Any way i opened a query with TAC lets see..
12-29-2004 04:57 AM
Onother way to troubleshoot that would be to put a packet sniffer to that interface.
Note: But a real packet sniffer that is able to see also physical problems, not all network cards are able to see them, they are silently droped.
sincerely
Patrick
12-31-2004 10:48 PM
Hi rohit,
Actually that is the problem with Linksys router, which is not accepting any changes in speed. After client replaces his router this problem is sorted out. Thanks for your help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide