PIX firewall NATing problem

PIX firewall NATing problem

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
PIX firewall NATing problem Yuriy 11-10-2006
Posted by Yuriy on November 10, 2006, 11:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I wonder is someone seeing something similar before.
I'm experiencing very strange problem but first briefly about
configuration.
I got PIX 515E v7.0(2) on the front and ISA Server and a couple of
other computers on DMZ zone.
So after some time of using internet trough ISA server, users loosing
ability to browse, there is no incoming SMTP messages as well, but
other computes on DMZ can access internet with no problem.
Usually simple restart of firewall will fix it.
Once i check translation state show xlate and it displays around 300 of
PAT translation to ISA server. I'm not sure if this is normal but after
running clear xlate, clients starts browsing internet again.

What is happening?
Any ideal will be appreciated.

Regards,
Yuriy.


Posted by uNiXpSyChO on November 10, 2006, 5:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yuriy wrote:
> Hi,
>
> I wonder is someone seeing something similar before.
> I'm experiencing very strange problem but first briefly about
> configuration.
> I got PIX 515E v7.0(2) on the front and ISA Server and a couple of
> other computers on DMZ zone.
> So after some time of using internet trough ISA server, users loosing
> ability to browse, there is no incoming SMTP messages as well, but
> other computes on DMZ can access internet with no problem.
> Usually simple restart of firewall will fix it.
> Once i check translation state show xlate and it displays around 300 of
> PAT translation to ISA server. I'm not sure if this is normal but after
> running clear xlate, clients starts browsing internet again.
>
> What is happening?
> Any ideal will be appreciated.
>
> Regards,
> Yuriy.
>

try upgrading to the latest version 7.0.6. 7.0.2 is more than a year
old and bug ridden.

Posted by CK on November 11, 2006, 8:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Can you post PIX config ??


Yuriy wrote:
> Hi,
>
> I wonder is someone seeing something similar before.
> I'm experiencing very strange problem but first briefly about
> configuration.
> I got PIX 515E v7.0(2) on the front and ISA Server and a couple of
> other computers on DMZ zone.
> So after some time of using internet trough ISA server, users loosing
> ability to browse, there is no incoming SMTP messages as well, but
> other computes on DMZ can access internet with no problem.
> Usually simple restart of firewall will fix it.
> Once i check translation state show xlate and it displays around 300 of
> PAT translation to ISA server. I'm not sure if this is normal but after
> running clear xlate, clients starts browsing internet again.
>
> What is happening?
> Any ideal will be appreciated.
>
> Regards,
> Yuriy.


Posted by Yuriy on November 13, 2006, 9:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

Thank you for your reply.
Unfortunately not. Company policy does not allow me to do so.
But I would appreciate any clues you have.

Regards,
Yuriy.

CK wrote:

> Can you post PIX config ??
>
>
> Yuriy wrote:
> > Hi,
> >
> > I wonder is someone seeing something similar before.
> > I'm experiencing very strange problem but first briefly about
> > configuration.
> > I got PIX 515E v7.0(2) on the front and ISA Server and a couple of
> > other computers on DMZ zone.
> > So after some time of using internet trough ISA server, users loosing
> > ability to browse, there is no incoming SMTP messages as well, but
> > other computes on DMZ can access internet with no problem.
> > Usually simple restart of firewall will fix it.
> > Once i check translation state show xlate and it displays around 300 of
> > PAT translation to ISA server. I'm not sure if this is normal but after
> > running clear xlate, clients starts browsing internet again.
> >
> > What is happening?
> > Any ideal will be appreciated.
> >
> > Regards,
> > Yuriy.


Posted by CK on November 13, 2006, 1:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Okay i understand the confidiantiality .

Do you have IP reverse path verify enable for IP Spoofing on both the
interfaces.
What is the idle time for minimum XLATE translation?


CK


Yuriy wrote:
> Hi,
>
> Thank you for your reply.
> Unfortunately not. Company policy does not allow me to do so.
> But I would appreciate any clues you have.
>
> Regards,
> Yuriy.
>
> CK wrote:
>
> > Can you post PIX config ??
> >
> >
> > Yuriy wrote:
> > > Hi,
> > >
> > > I wonder is someone seeing something similar before.
> > > I'm experiencing very strange problem but first briefly about
> > > configuration.
> > > I got PIX 515E v7.0(2) on the front and ISA Server and a couple of
> > > other computers on DMZ zone.
> > > So after some time of using internet trough ISA server, users loosing
> > > ability to browse, there is no incoming SMTP messages as well, but
> > > other computes on DMZ can access internet with no problem.
> > > Usually simple restart of firewall will fix it.
> > > Once i check translation state show xlate and it displays around 300 of
> > > PAT translation to ISA server. I'm not sure if this is normal but after
> > > running clear xlate, clients starts browsing internet again.
> > >
> > > What is happening?
> > > Any ideal will be appreciated.
> > >
> > > Regards,
> > > Yuriy.


Similar ThreadsPosted
NAting and Port forwarding September 21, 2006, 6:46 pm
Bidirectional nating using an Windows server March 24, 2006, 1:28 pm
nortel softphone to access BCM behind NATing FW September 27, 2007, 7:57 pm
Possible firewall problem? August 28, 2004, 10:21 pm
Is this a firewall problem? March 24, 2005, 10:38 pm
IIS/firewall problem August 26, 2005, 7:01 pm
PIX 501 firewall - DNS problem October 31, 2005, 7:45 am
May be a Firewall Problem! May 23, 2006, 11:27 am
Re: firewall problem with ftp November 26, 2006, 12:25 pm
Re: firewall problem with ftp November 27, 2006, 6:51 am

The site map in XML format XML site map

Contact Us | Privacy Policy