Solved

Cisco routers stop working until reboot

Posted on 2003-11-03
5
728 Views
Last Modified: 2012-05-04
We have about 300 cisco routers connecting our stores to a private network. These routers are a mixture of 1721's and 827's. I am not a cisco router expert, so I need some expert advice. Every once in a while these routers will stop working. You can still connect to the terminal on the external port. If we physically shut down the router and power it back up it works fine. Is there a way to reboot the router from the terminal. Is there another solution. This may be a very common problem.

These routers perform nat and on the dsl stores that use the internet there is 3des encryption.
0
Comment
Question by:mrconover
5 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 100 total points
ID: 9672191
This is not a common problem. If it happens routinely, there is a problem that needs to be investigated.
Common causes are CPU or Memory overload. Latest batch of virus/worms - specifically Welchia and MSBlast - cause these denial of service symptoms due to the extreme amount of icmp traffic looking for other hosts to infect. I would almost bet money that your network is infected.
If you can still connect to vty term (telnet), you can reboot with "reload" command.
i.e.
router#reload
Proceed with reload? [confirm] <enter>

Now just pray that you get connection back in a couple of minutes..

Another common cause is CPU overload caused by too much traffic for the CPU to handle (3DES encryption on a heavy-use VPN tunnel). If it is more common on the 827's than on the 1721's, they have a smaller CPU and less memory to work with.
Sometimes a Cisco engineer will turn on a debug and forget to disable it.
Before you reload, take a look and see if any debugs are turned on:
No debugs running:
Router#sho deb
Router#

Else:
Router#sho deb
Generic IP:
  IP NAT debugging is on
UDP:
  UDP packet debugging is on
Router#

Turn off all debugging:
Router#u all  <short for "undebug all">
Make sure you are at the global router# prompt, and not in config mode:
Router(config)#u all
Now I've just created a username "all" with no password, and the debugs are still running..
0
 
LVL 3

Assisted Solution

by:sheahmed
sheahmed earned 100 total points
ID: 9676503

i guess u should try this command on your other router as well ...

router#sh ver

this will display you the very basic information of your router inclding the reason of last reboot ...

like ...
-----------------------------------------------------------------------
new-tdma uptime is 10 weeks, 2 days, 5 hours, 6 minutes
System returned to ROM by power-on
System image file is "flash:c2500-dos-l.122-16a.bin"  
------------------------------------------------------------------------

you can get some error report instead of power on ...

Try this access-list on your core interfaces first and then monitor the traffic? are u satisfied with the current traffic load? ... it can certainly block blaster, nache, welchia ...

access-list 120 deny   tcp any any eq 445
access-list 120 deny   udp any any eq 445
access-list 120 deny   tcp any any eq 4444
access-list 120 deny   tcp any any range 135 139
access-list 120 deny   udp any any range 135 netbios-ss
access-list 120 deny   icmp any any
access-list 120 permit ip any any    


sheeraz ahmed
0
 

Expert Comment

by:asgarali
ID: 9918777
hi

its definetly not a commn prob  you should have alook at the buffers and cpu load on the routers which  stop processing
you could chek the ios versions and have the latest once ios upgraded,  have the buffers size fine tuned and have ur cahce timeout speicified.



stack
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now