08-29-2008 01:39 PM - edited 03-11-2019 06:37 AM
I have a site to site VPN setup using a PIX 515e as the hub termination point at our data center. I have a PC at the remote site that traverses that PIX to get to a database on an IBM AIX server at the data center. This database connection never used to time out or drop prior to putting them on this VPN connection. (The site used to be directly connected with a 64k link). The entire site never drops or goes down, we have several monitors in place monitoring routers/servers etc. at that site that remain solid even when this database connection dies. Any thougts on how/why this db connection is continually dropping regardless of activity? Thank you.
08-30-2008 08:06 AM
It could be the vpn related idle-timeout or a generic timeout on the PIX firewall.
You would have to monitor the 'show conn det | inc
Regards
Farrukh
08-30-2008 03:50 PM
I ran into an exact situation like yours, remote
PC with ODBC connection to an IBM AIX Server
running DB-2 database over a VPN with Pix as
the VPN termination. The ODBC connection
timeout even when the VPN tunnel is up and
running (I can confirm this because I have
a constant ping from the PC to the AIX Server
and with no ping loss.
I resolved the issue by terminating the VPN to
a Cisco 2811 router and just let the Pix
inspect the traffic after the traffics get
encrypted/decrytpted by the VPN router. After
that, the issue goes away.
I was under pressure to make this work so I
did not spend much time troubleshooting the VPN with Pix as the VPN termination endpoint,
but it is definitely the pix that caused this.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide