Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Pix Crash! Reboot No PDM - Telnet

Status
Not open for further replies.

DKMOORE

Technical User
Apr 19, 2002
26
US
While out on a medical our network came to a screehing hault!
It seemed to be a DNS problem. Internal DNS proved to be working fine. Some clients had access to outside, most did not.
I suggested a reboot of the 1721 Router and PIX515E. This fixed the problem. (I guessing from what I've read here it may have been an xlate issue on the PIX).

Anyway when I got in I tried to access the PIX via the PDM, no go! Then I connected using telnet on inside addr to check config, etc. I was getting double characters, and the password was being displayed? I connected via the console all was well.

Then i tried to connect via telnet, no I cant connect!

So NO TELNET
NO PDM
ONLY CONSOLE

Any IDEAS!!
 
The telnet problem sounds like local echo is "on" in the client.

As for PDM, maybe the computer you're using isn't authorized? Perhaps it was, but the configuration hadn't been written to NVRAM.
 
Thanks for the response lgarner

I get a response -
Connecting To 172.16.10.1...Could not open a connection to host on port 23 : Connect failed

I have checked the config and telnet and http enabled. There seemed to be a problem with the Names settings -
I went to delete the http "name" statement
And it responded with no such ip address, although it was defined in the name statement. So something is messed up.
I may just reload and recreate the config. It's not that complicated - I was just wondering if anyone had seen this kind of problem before. Trying to determine if it's hardware or just gremlins...

I will post config soon!
 
PDM can fail if the crypto keys on the PIX become corrupted, you can regenerate these if necessary if you have console access, but it doesn't sound like that's the problem in this case ... you could always just allow pdm and telnet access from any address on your local subnet for a moment to see if it is that

CCNA, MCSE, Cisco Firewall specialist, VPN specialist, wannabe CCSP ;)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top