cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
796
Views
0
Helpful
1
Replies

PIX timeout/keep-alive

mueti
Community Member

After installing PIX 515, version 6.3.3, I get connection problems between a client-server-system (inside -> dmz). The client sends persistent (all 3 minutes) a refresh (tcp port greater 1024) over a defined port which is allowed in access-list to the server. But after 2 hours the connection break down and I have to initialise a new connection from client. All timeouts are standard settings and nothing is configured for 2 hours, no authentication is used! What´s going wrong. How can I solve this problem.

Many thanks.

Helmut

1 Reply 1

ehirsel
Level 11
Level 11

I would run two capture statements on the pix:

One on the interface closest to the client and the ohter on the interface closest to the server.

On the client side, code an acl as follows:

access-l cap01 permit ip host client-ip host server-ip

access-l cap01 permit ip host server-ip host client-ip

where client-ip is the true address of a client (use only one cliet for this test to make the troubleshooting easier) and server-ip is the server address as seen by the client.

On the server intf capture you would code a similar acl using cap02 as the acl name with these notes: client-ip will be the client's address as seen by the server so if you are using nat/pat for these connections, then it will be whatever you nat/pat to. Server-ip is the true ip address of the server.

You can run multiple capture statements one using acl cap01 in client intf and the other usering acl cap02 on the server intf at the same time.

Please post both capture results here after the error occurs. You can use a packet-l of 256 and a buffer of 40960 or higher - and you may want to do this when there is little production traffic or load on the pix.