I agree with chicouk,
apply using
access-group acl_out in interface INSIDE
fixup protocol ftp 21
write mem
then try connecting and do:
show access-group acl_out
and look at your counters.
at least then you'll know if you are traversing the firewall or getting hung-up in IIS.
MCSE/MCDBA...
I have 6 NICS in my PIX
(don't worry this isn't a poem)
I have active networks on all NICS.
Wondering...instead of using the failover cable, can I failver via NIC...even if it's on an active network? Or do you have to use a x-over from one NIC to another if you are using NICS to failover...
yeah this may be part of the problem...but the oddity is the fact that all of the interfaces on my add-in card are running very slow. While onboard nics E0 and E1 are blazing still.
We're going to fix the outside interface to router sometime today...I don't think it's going to fix the other...
I think this may be attributed to the router 10.75.255.1 being configured as auto-negotiate while the pix is set manually.
I've contacted the router administrator to get the scoop on this. BUT, I don't know if this directly relates to the problem I'm having on the other interfaces...
just noticed my outside interface plugged into a router is showing this:
interface ethernet0 "outside" is up, line protocol is up
Hardware is i82559 ethernet, address is xxxx.xxxx.xxxx
IP address 10.75.255.2, subnet mask 255.255.255.0
MTU 1500 bytes, BW 100000 Kbit full duplex...
PIX 525 with 5 interfaces
inside
zone1
zone2
zone3
outside
Are my inside and outside interfaces sucking up all my bandwidth or something? Outside shows 4020 packets/sec
inside shows 1002 packets/sec
while zone1, zone2, zone3 are cooking along at less than 20 packets a second...some are as low...
On a PIX 525 what's the USB port for?
I tried looking through documentation and running a few searches but I couldn't seem to find out what it's all about.
any insight would be appreciated.
MCSE/MCDBA
SANS GIAC + SANS FIREWALL
SMS 2003 is in release canidate 1 we are currently evaluating it. Rather funny, considering we have never played with any previous versions of SMS.
Anyways, we're having problems with the most basic of things. We are unable to "push" out the client. We were initially receiving an...
yeah I know UDP isn't as reliable as TCP. I just wasn't aware that the pix would "crap out" when it isn't connecting to the syslog server!!
I'm sure everyone can appreciate the humor in my silly-arse running around ripping my hair out because the firewall "Suddenly and...
Oh yeah...Like I said, I currently have logging disabled, I'm wondering if I re-enable it on TCP...and I EVER encounter this problem again, how do I resolve it? Do I need to reset the Pix or just turn the logging server back on...or do I need to turn logging off on the Pix and turn it back on...
I love you man! Yes it is TCP logging! (turned off last night in an effort to get things running)
If I switch it to UDP will it make a difference...what do you recommend?
I can understand why it would do that...for security reasons, but I don't remember having read anything about that...
I have it working again, so this can wait until the morning, I just can't have this happening on a regular basis...not sure what is causing this particular problem. I suspect it has something to do with logging, but I cannot be sure.
Basically here is what I am experiencing:
Pix runs fine for...
this is an internal firewall that we use to restrict access to employees. =)
I like the hit counters, because it allows me to see which rules haven't been used since we deployed the pix.
It's about time to scrub the list...right now I have over 1400 lines in my pix config!!!
MCSE/MCDBA
SANS...
Hello,
I'm wondering if anyone has come across a tool that not only logs events, but also displays the hit-count on the access lists?
The only way I can see now is to print out my current configuration, and login to the pix, and view each line for number of hits and mark on my sheet.
The...
I don't control the router =(
My arrangement is a little unconventional. The pix is NOT running at the perimeter, it's actually an internal firewall to aid in securing vital financial servers. We use it to make sure employees aren't playing around where they shouldn't be.
So everything...
btw-I'm thinking the reason you can't telnet to the device is because your address isn't "allowed" to telnet...have to use hyperterminal first.
MCSE/MCDBA
SANS GIAC + SANS FIREWALL
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.