04-16-2004 06:30 AM - edited 03-02-2019 03:02 PM
We've had a 2621 router for some time now, configured the same way for months. Beginning a couple weeks ago we've noticed HTTP return traffic stopping for no reason, and the only way to fix it is to wait for the router to correct itself somehow (15-20 minutes) or reload the router.
The IP cache flow shows no unusual traffic internally or externally, and all other traffic (smtp, vpn, etc.) flows normally.
The router is locked down to prevent any kind of worms and such. The only ports open are smtp, http, 1723 and a few others. I would expect a denial of service attack would be noticable.
I think it's a NAT problem... but I'm not sure how to check it, nor am I sure why it just started happening.
Any help would be appreciated.
Thx,
Eric Swartz
Information Systems Team Leader
Ransohoff, Inc.
04-16-2004 11:40 AM
If it is a nat problem it should be visable with an show ip nat statistics command.
The number of entries should not exceed 5000 to keep your router working correctly,
If it is high you could try clearing your nat translations by giving the clear ip nat trans * command.
HTH
Tom
04-19-2004 12:57 PM
I guess I was wrong. It must not be NAT as I haven't seen more than 180 or so active translations in the times I checked it. When HTTP traffic went down (several times today) I checked and we only had 80 or so active translations.
HTTP traffic came back after about 15 minutes or so.
Any other ideas?
Thx,
Eric
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide