I have it working again, so this can wait until the morning, I just can't have this happening on a regular basis...not sure what is causing this particular problem. I suspect it has something to do with logging, but I cannot be sure.
Basically here is what I am experiencing:
Pix runs fine for undetermined period of time. Then, sometimes without cause(?) it failes(?) shut. It's interesting because my access-lists still show hits in some cases, however; the pix is not routing packets.
Say I have access-list that allows ping between DMZ and INSIDE
I can go to DMZ and ping InsideHost and get no response
I look at access-list count, and it has incremented.
I go to inside host and ping DMZ host, and get no response.
I look at access-list count, and it has NOT incremented.
I SUSPECT that this may be attributed to me having logging turned on, then my sys-log service was taken offline for a short period of time...is this possible? Is there a key configuration that I am missing.
I ran my pix for several months without problems, it's when I started logging packets and taking a close look at what was happening that I started having this problem.
This is the second time I have experienced it. It hit me when I terminal serviced to my administrative server into the PIX. I wanted to look at the logs, I went to launch the viewer and it said it was already running (via another terminal service session left opened). I killed the service and that's when the system got really slow and stopped responding. I quickly realized that all hosts behind the firewall were unreachable...I hopped in the car and frantically drove to my worksite...where I've been for about 3 hours now.
Any insight you can offer would be greatly appreciated. Sorry if I am rambling, it's late...and I am stressed.
MCSE/MCDBA
SANS GIAC + SANS FIREWALL
Basically here is what I am experiencing:
Pix runs fine for undetermined period of time. Then, sometimes without cause(?) it failes(?) shut. It's interesting because my access-lists still show hits in some cases, however; the pix is not routing packets.
Say I have access-list that allows ping between DMZ and INSIDE
I can go to DMZ and ping InsideHost and get no response
I look at access-list count, and it has incremented.
I go to inside host and ping DMZ host, and get no response.
I look at access-list count, and it has NOT incremented.
I SUSPECT that this may be attributed to me having logging turned on, then my sys-log service was taken offline for a short period of time...is this possible? Is there a key configuration that I am missing.
I ran my pix for several months without problems, it's when I started logging packets and taking a close look at what was happening that I started having this problem.
This is the second time I have experienced it. It hit me when I terminal serviced to my administrative server into the PIX. I wanted to look at the logs, I went to launch the viewer and it said it was already running (via another terminal service session left opened). I killed the service and that's when the system got really slow and stopped responding. I quickly realized that all hosts behind the firewall were unreachable...I hopped in the car and frantically drove to my worksite...where I've been for about 3 hours now.
Any insight you can offer would be greatly appreciated. Sorry if I am rambling, it's late...and I am stressed.
MCSE/MCDBA
SANS GIAC + SANS FIREWALL