cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
306
Views
0
Helpful
3
Replies

Stop accessing Internet in 30 minutes

blin
Level 1
Level 1

We have PIX515 with V6.3.(3). Since yesterday, we have this problem: If we clear xlate and reload the firewall, all users can access the internet for a while. After a few minutes, it starts to drop some machines while other machines still work. After half hour or 1 hour, no one can access the intrenet any more. Then rebooting works for a while.

How can I tyroubleshoot this issue?

3 Replies 3

sachinraja
Level 9
Level 9

Hi,

Can you set the arp timeout and xlate timeout to a larger value (say 3 or 4 hours ) ?? try doing this and see if it solves ur issue..

am sure when the problem is there, NAT doenst happen.. right ?? see if you have enabled logging.. disable it and see if it solves the issue...

Raj

You should probably do a netstat -a on a machine to see if you have a trojan or call-home virus or something. My suspicion is you have something in your network doing a port scan or something using up all your DNAT allocations and hence killing your PIX

Hi

Thank you for replies. Found the problem. We just added one Promise Vtrak storage that is using the same ip of the Firewall by default.