Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Clear Xlate Issue

I have a 515e PIX with 6.3.

About once every few weeks I get an issue where my internal clients on the inside interface cannot reach our web based services from the inside. The users that access them from the outside have no issue. If I clear xlate the issue goes away for a few weeks again.

What could cause this ? If there is no obvious reason why this is happening is it possible to script something or a way to clear the translation tables automatically at a set time like 3am ?

Thanks for any thoughts.

  • Other Security Subjects
7 REPLIES
New Member

Re: Clear Xlate Issue

can u post ur configs??

i think that will hjelp a lot..

i think that problems is cause ur xlate table gets filled...

You shuldt be having this problem for outside users cause u would have static natted ur servers with a public IP....thus pix would have created a permanent entry into the xlate table.....

but for inside users....the entries xlate table will be dynamic......so once the table gets filled new users will not be able to reach the server...

Re: Clear Xlate Issue

can you post the output of show timeout

New Member

Re: Clear Xlate Issue

Thanks for your responses.

----------------------------------------------------

Here are the contents of sh timeout

***-Wall# sh timeout

timeout xlate 3:00:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00

timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00

timeout uauth 0:05:00 absolute

***-Wall#

--------------------------------------------------

--------------------------------------------------

The version of the PIX IOS is 6.3(4) so the I guess isn't the issue. I am curious if upgrading to 7.0 might benefit me though and is it a simple process or painful.

---------------------------------------------------

I am editing my config for posting and will get it up shortly.

Thanks again for your thoughts on this.

New Member

Re: Clear Xlate Issue

If you are using PIX Version 6.2(2) perhaps bug CSCdy58717 try upgrading to PIX 6.3(x)

New Member

Re: Clear Xlate Issue

Attached is my config.

aaa.bbb.ccc = IPs on the outside

111.222.333 = a 3rd party email scanning network

192.168.10.x = represents my inside network

192.168.20.x = represents my DMZ Network

Re: Clear Xlate Issue

hi .. you config seems OK .. what about the licensing part .. show version

You could also reduce the xlate timeout from the default 3 hours ...

I hiope it helps ... please rate if it does !!!

New Member

Re: Clear Xlate Issue

One more thing to add that may be an issue. Our external domain name is the same as the domain name for our MS Active Directory. While I a sure that our DNS is configured correctly, this may or may not be an issue.

Just thought I'd add that. Anyone with any thoughts ?

153
Views
0
Helpful
7
Replies