PIX losing responses from one particular DMZ website

Unanswered Question
Mar 31st, 2010

We have a PIX 525 running 7.2(2). Recently, without any network changes, one particular webserver in the DMZ network became unreachable. Other webservers in that same network can be reached as normal. In doing packet captures both inside and in the dmz, it looks like the page request goes out and the page comes back and gets as far as the dmz interface. In packet captures on the inside network, an ACK is received from the server for the page request, and that's the last thing received on that session. Subsequent attempts seem normal until that point, too.

We have a standby PIX and we've tried doing a failover to that, and that device is showing the same behavior.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
JORGE RODRIGUEZ Wed, 03/31/2010 - 14:24

From your description sounds  like an issue with Webserver than a firewall issue,  provided your indication of other webservers in same DMZ network have no problems ,  have you look at app event logs etc..  from  the server itself to rule out any issues with it before moving onto looking other posibilities?


spfister336 Thu, 04/01/2010 - 05:30

That's what I thought at first, but packet captures show a normal response up until the dmz interface of the PIX. The inside interface captures (and I'm assuming the outside interface, too) show no response after the ACK to the page request.

JORGE RODRIGUEZ Thu, 04/01/2010 - 09:35

When you say server unreachable what is the server suppost to be reponding on  port 80 ..   and what sources are  connecting to it  inside, outside ?

Can you post packet trace  accessing DMZ server from inside ?

packet-tracer input inside tcp      detailed


Also please ensure to rule out any physical issues , look at all physycal interfaces transmission , from the server side,  and DMZ interface as well  to make sure there is no packet drops.



This Discussion