cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
240
Views
0
Helpful
1
Replies

ARP on Catalyst6500 doesn't update the MAC address of a PIX 515E

foxpreacher
Level 1
Level 1

I have seen someone put this thread on other forum,but i can't settle the problem.follow is the question.The network has a Catalyst 6500 be a core switch and down link to a Catalyst 2950, and Catalyst 2950 down link to a PIX 515e firewall, as below...

C6500

|

|---(Public Network)

|

C2950

|

|---(Public Network)

|

PIX515e

|-----3 servers on DMZ

|

(Inside Protected Network)

I'm using Static NAT maps addresses of the several servers beside a DMZ port and using PAT for inside network. The problem is that when everything has ran for a few minutes then the servers on a dmz can not reach the public network, the public network can not reach the servers also. I have to clear the ARP cache on a C6500 to let it works again. This problem does not occur with the inside network that is using PAT translation.

1 Reply 1

Bradley Littlejohn
Cisco Employee
Cisco Employee

Does the problem still occur when you ping with the "record" option? Does it work if you disable mls on the vlan? "no mls ip" under the vlan interface.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: