11-21-2005 12:56 PM - edited 03-03-2019 11:02 AM
Have spent weeks troubleshooting and trying different configurations. Trying to replace a cheapo Efficient Networks DSL modem with a Cisco 1841. Right now have the config stripped down of the more common security aspects for troubleshooting purposes (and since I've been through so many tweaks it's entirely possible something is mixed up now)
Topology is:
internal LAN---switch---Checkpoint FW1---old 3COM Superstack 3300 switch---Cisco 1841 w/ADSL card---internet
DSL circuit plugged directly into Cisco ADSL. Static IP obtained from provider (Frontier Communications).
Goal is to allow internal uses internet access and external SMTP in.
Problem is everything works fine for anywhere from 2 hours to two weeks, and then suddenly you can't access the web anymore. From my limited debugging ability, I don't see any problems (arp cache doesn't look too big, cpu history occassionally hits 60-70%, but mostly low, nat translations around 100). Mail is still coming in though.
If I reload the router it comes back up. If I take out the router and put the cheapo Efficient Networks DSL modem back in things work fine for as long as I want. The Checkpoint firewall has been in place for years with no problems. Not sure if it has an impact, but both the Checkpoint and Cisco are performing NAT. Will have to think that through.
Any input is greatly appreciated.
Brian
Config is attached
11-21-2005 01:31 PM
Brian
This is a pretty interesting puzzle. When I first read your description of how the router would intermittently stop access outside my reaction was to think that it was some issue on the ADSL interface. But when you said that mail continues to work I thought that it could hardly be an interface issue.
I am wondering if it may be an issue with address translation. SMTP has a static translation and keeps working (if I have understood the description properly) while things that are dynamically translated stop working. The next time that it starts not working, would you be able to clear the translation table before you reboot and see if that changes anything?
HTH
Rick
11-30-2005 01:51 PM
Sorry Rick, I didn't see your response before I posted my last plea. I will try that next time (clear nat?). I've got to put the router back online/inline first which can only do early hours.
Also, I need to double check that mail is still working-99% sure but I might have missed something. I do know reloading clear the problem out.
Thanks for your input.
Brian
11-30-2005 01:43 PM
Can anybody suggest anything to watch for? Anything?
Brian
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide