04-23-2003 01:05 AM - edited 02-20-2020 10:42 PM
I have configurated my pix 515 (ver. 6.22) to logging to my webtrend server
everything seems ok ,the logging level is debugging
but something wrong
all my hosts on inside can not use DNS to reslove DNS (port 53 )name to access the internet , my network is ok !!! (I have check all my routers, L3 switch , pix .etc ,and I try to ping and use the the real ip address to access to some web site on internet, like http://real ip address , the connection is ok!!,
then I try my own DNS inside and the other Isp DNS , but can not work
until I disable the logging on my pix filewall
IT is a very strange problem , why ??
04-23-2003 12:49 PM
HI.
If you're logging via TCP, try logging via UDP and see if it changes anything.
With TCP logging, the pix does not allow traffic until it can log it. So it might be waiting for confirmation from the syslog server, and maybe this causes DNS timeouts, especially if you have a high load.
With UDP logging, the pix allows the traffic and sends the syslog message (without waiting for confirmation).
Anyway, it is recommended to configure all internal hosts to use internal DNS servers, and only the internal DNS servers to forward to ISP servers when needed.
Yizhar
04-23-2003 09:12 PM
Hi,
Can you nslookup from internal lan any internet host
1) Behind the PIX
2) Without PIX
rgds
richard
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide