cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
446
Views
5
Helpful
6
Replies

PIX 515 web traffic problem

prafuljaded
Level 3
Level 3

Hi All,

My proxy setup is as below.

Proxy-->L3 switch GW-->PIX inside

Sometimes suddenly the web internet access stops from inside. I have PAT configured on the PIX for outbound.I am able to ping/resolve internet addresses from inside routers/PCs with no problem when this is happening.The web traffic stops working with or without proxy server settings in the Internet Explorer.Sometimes 'clear xlate' fixes the problem.I am running 6.3(4)

Thanx,

Praful

6 Replies 6

vasthorvak
Level 1
Level 1

check dns requests in your translation table when this is occuring and now that are initiated from your proxy. If you see alot of embryonic connections from this host for dns request then you will need to increase your dns fixup max size to something like 1024 from the default 512.

Hi Kevin,

I have changed the command to 'fixup protocol dns maximum-length 1024'. Is that what you meant ? But that allows DNS packets more than default 512 bytes

Thanx,

Praful

Yes that is correct. You want to do this if you are seeing in your syslogs (if you are logging to at least level 5 notifications) dropped dns packets due to the packet size being to large. You will also see alot of half open connections because the dns query went out and the packet was dropped by the pix but it did not tear down the session until it times out. Then the server will send out another request and the same thing happens so over time the connections will get eaten up and then the pix chokes. You might want to temporarily change it back and take a close look at your connection table and syslogs for any suspicious traffic. Once you find the culprit then you can clear the xlate or conn for just that IP and then reset the fixup back to 1024 or more. Even if you do keep the fixup at a higher level I would still recommend that you watch it closely for any suspicious traffic. Also watch the cpu and memory usage.

jackko
Level 7
Level 7

please advise the pix model

Its PIX 515 as mentioned in the subject field.

Thanx Kevin..I was seeing some DNS reply reject messages on the PIX when the default of 512 Bytes was configured. Now its 1024 and CPU and memory usages are looking OK.I will keep a closer look on them.

Praful

Hi All,

I guess I figured out the problem. We have an internet router infront of the PIX and we have denied some TCP ports in the range (for reverse tenet) 2001 to 7099 as below.

deny tcp any any range 2001 2999

deny tcp any any range 3001 3099

deny tcp any any range 6001 6999

deny tcp any any range 7001 7099

This router was blocking ports in these range and we had intermittent problems.So PIX is not the culprit.

All http requests back which fell in this port range were getting dropped.

Thanx All,

Praful

Review Cisco Networking products for a $25 gift card