07-03-2006 07:06 AM - edited 03-09-2019 03:28 PM
I have a 515e PIX with 6.3.
About once every few weeks I get an issue where my internal clients on the inside interface cannot reach our web based services from the inside. The users that access them from the outside have no issue. If I clear xlate the issue goes away for a few weeks again.
What could cause this ? If there is no obvious reason why this is happening is it possible to script something or a way to clear the translation tables automatically at a set time like 3am ?
Thanks for any thoughts.
07-03-2006 10:51 AM
can u post ur configs??
i think that will hjelp a lot..
i think that problems is cause ur xlate table gets filled...
You shuldt be having this problem for outside users cause u would have static natted ur servers with a public IP....thus pix would have created a permanent entry into the xlate table.....
but for inside users....the entries xlate table will be dynamic......so once the table gets filled new users will not be able to reach the server...
07-03-2006 06:06 PM
can you post the output of show timeout
07-05-2006 08:47 AM
Thanks for your responses.
----------------------------------------------------
Here are the contents of sh timeout
***-Wall# sh timeout
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
***-Wall#
--------------------------------------------------
--------------------------------------------------
The version of the PIX IOS is 6.3(4) so the I guess isn't the issue. I am curious if upgrading to 7.0 might benefit me though and is it a simple process or painful.
---------------------------------------------------
I am editing my config for posting and will get it up shortly.
Thanks again for your thoughts on this.
07-04-2006 05:26 PM
If you are using PIX Version 6.2(2) perhaps bug CSCdy58717 try upgrading to PIX 6.3(x)
07-05-2006 10:58 AM
07-05-2006 06:37 PM
hi .. you config seems OK .. what about the licensing part .. show version
You could also reduce the xlate timeout from the default 3 hours ...
I hiope it helps ... please rate if it does !!!
07-06-2006 12:22 PM
One more thing to add that may be an issue. Our external domain name is the same as the domain name for our MS Active Directory. While I a sure that our DNS is configured correctly, this may or may not be an issue.
Just thought I'd add that. Anyone with any thoughts ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide