02-16-2005 01:56 PM - edited 03-09-2019 10:21 AM
We have PIX515 with V6.3.(3). Since yesterday, we have this problem: If we clear xlate and reload the firewall, all users can access the internet for a while. After a few minutes, it starts to drop some machines while other machines still work. After half hour or 1 hour, no one can access the intrenet any more. Then rebooting works for a while.
How can I tyroubleshoot this issue?
02-16-2005 11:28 PM
Hi,
Can you set the arp timeout and xlate timeout to a larger value (say 3 or 4 hours ) ?? try doing this and see if it solves ur issue..
am sure when the problem is there, NAT doenst happen.. right ?? see if you have enabled logging.. disable it and see if it solves the issue...
Raj
02-17-2005 07:14 AM
You should probably do a netstat -a on a machine to see if you have a trojan or call-home virus or something. My suspicion is you have something in your network doing a port scan or something using up all your DNAT allocations and hence killing your PIX
02-17-2005 12:17 PM
Hi
Thank you for replies. Found the problem. We just added one Promise Vtrak storage that is using the same ip of the Firewall by default.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide