cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
331
Views
0
Helpful
2
Replies

pix 515 logging problem

mingchieh
Level 1
Level 1

I have configurated my pix 515 (ver. 6.22) to logging to my webtrend server

everything seems ok ,the logging level is debugging

but something wrong

all my hosts on inside can not use DNS to reslove DNS (port 53 )name to access the internet , my network is ok !!! (I have check all my routers, L3 switch , pix .etc ,and I try to ping and use the the real ip address to access to some web site on internet, like http://real ip address , the connection is ok!!,

then I try my own DNS inside and the other Isp DNS , but can not work

until I disable the logging on my pix filewall

IT is a very strange problem , why ??

2 Replies 2

yizhar
Level 1
Level 1

HI.

If you're logging via TCP, try logging via UDP and see if it changes anything.

With TCP logging, the pix does not allow traffic until it can log it. So it might be waiting for confirmation from the syslog server, and maybe this causes DNS timeouts, especially if you have a high load.

With UDP logging, the pix allows the traffic and sends the syslog message (without waiting for confirmation).

Anyway, it is recommended to configure all internal hosts to use internal DNS servers, and only the internal DNS servers to forward to ISP servers when needed.

Yizhar

gomesrichard
Level 1
Level 1

Hi,

Can you nslookup from internal lan any internet host

1) Behind the PIX

2) Without PIX

rgds

richard

Review Cisco Networking products for a $25 gift card