Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Netscreen Crashing Server...

Status
Not open for further replies.

boodox

MIS
Sep 24, 2002
54
GB
Hi There,

I've got a netscreen problem that I need some help with.

I've got a server running a custom developed UHF (aerial) based application. Whenever the server operates by itself or on a basic LAN, the application works perfectly and
doesn't crash.

When there is a netscreen in between, it works and is fully accessible but the application on the server will then crash and the most annoying thing about it is that it's completely at random. Unfortunately, this server needs to go behind a firewall otherwise I'd leave it on the LAN where it is.

All of the necessary ports, rules, groups and policies have been defined (otherwise the application wouldn't work at all) and the server itself is fully accessible (which has been tested repeatedly). I've had stable operation and connectivity to the server and application with anything from 10 minutes to 7 days at a time using the same rule base but it will crash and after a random amount of time.

I've spoken with the developers of the UHF application and they've said the application is not intelligent enough to detect the difference between any device it's connected to a network through (be it Firewall, Switch, Hub or whatever)

They also said fact that the server and the application DOES work through it (which proves the rules and policies are correct) and it only crashes the application whenever the netscreen is put between it indicates the Netscreen possibly needs additional config.

Has anyone experienced anything similar or does anyone have any suggestions as to fix this? I would REALLY appreciate the help.

Thanks, in advance,

bdx
 
What mode do you have the Netscreen operating in? Have you try putting the Netscreen in Transparent Mode or layer 2 mode? Also have you check the logs? What version of ScreenOS are you using? Can you please post your configuration.

 
Hi sikek,

It's running in full firewall mode. I'm testing the access on a 5XP running 4.0.0r6.0 for the moment (with only Trust/UnTrust interfaces) This is just for testing purposes because it will be moved onto a NS-208 once I've got this working which unfortunately, given the nature of this firewall, cannot be set into Transparent mode.

Any ideas?
 
Can you please post your configuration? What ports are used by your application? Well what i mean is does your application requires that the original packet information be maintained?
Because disabling NAT,PAT or both will address this issue. It's recommended to disable PAT first. Have you also gotten the output of the Debug flow basic,Get dbuf stream or Get session? At the time of the server crashes?Because you can set it to debug flow processors and then check it after the server crash. I hope some of this information will help.

 
I'd forgotten about this thread completely. Disabling NAT/PAT didn't work but after much deliberation, it was agreed that this server no longer had to go behind a firewall and is working fine without it.

Thanks for the tips sikek!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top