Advertisement

07.31.2007 at 10:45AM PDT, ID: 22732470 | Points: 500
[x]
Attachment Details

Cisco Pix disconnects random Internet surfers

Asked by neolore in Network Routers, Miscellaneous Networking, Cisco PIX Firewall

Tags: pix, cisco, disconnect

Problem:
Random network users are unable to surf out the Cisco Pix for no apparent reason.  The length of time they are not able to access the Internet is also random.  Internet loss duration can be anything from 5 mins to whatever. While 1 user can access the Internet, another can not, even going to the same webpage.  While the user is 'disconnected' from the Internet they are unable to access any service MSN, FTP etc... so it is a complete lockout.  Then magically after a unspecified period of time, the user is able to access the Internet.

Environment:
* Cisco Pix 501 v6.3.5 connected to ADSL static IP - no authentication required for ADSL
* External interface of Cisco Pix is set identically to the ADSL modem interface 10M FULL DUPLEX
* Windows XP SP2 fully patched workstation connect to a Windows 2003 R2 server fully patched for DHCP.  DNS on workstations is configured to the Windows 2003 domain controller 192.168.1.10 only.
* Cisco Pix has the fixup DNS 1024, and the server has EDNS turned off

Trials:
* Replaced cables that connect to the ADSL modem and the switch - no effect
* Eliminated the server as the problem (connected a laptop to the network with a static IP address, and the laptop losses Internet)
* Eliminated the workstation as the problem (reformat a workstation and installed from scratch, same problem occurs)
* Clearing XLATE does not resolve the problem.  No XLATE errors.
* Utilization is below 10% - even during time of disconnect.
* 5 Cisco Engineers has looked at the config and all say it is OK.
* Replaced Cisco Pix anyways - problem persists.
* Replace Cisco Pix with generic Linksys router - problem went away therefor the problem is with the Cisco Pix.

Running out of ideas but for sure it is the Cisco Pix.  I find it very difficult to believe that 2 Cisco Pix are defective in the exact same manner.  If it is a programming issue, why is it that 5 engineers have verified that it is configured correctly.

Looking for help....

Start Free Trial
[+][-]07.31.2007 at 10:51AM PDT, ID: 19602589

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.31.2007 at 10:57AM PDT, ID: 19602638

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.31.2007 at 11:07AM PDT, ID: 19602727

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.31.2007 at 11:29AM PDT, ID: 19602904

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.31.2007 at 07:43PM PDT, ID: 19605942

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.01.2007 at 05:03AM PDT, ID: 19607928

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.01.2007 at 06:01AM PDT, ID: 19608288

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.13.2007 at 06:32AM PDT, ID: 19883442

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.13.2007 at 07:44AM PDT, ID: 19884092

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32