PIX 506 Duplex speed change

Posted on 2004-08-30
Last Modified: 2007-12-19
I want to change the internal interface speed. For some reason my download speed has decreased to 70 Kbps. I have reset the pix a few times and reset the modem, the switch is new. I want to change the duplex speed on my internal interface. but it says..
ethernet1 can only be set to 10baseT, 10full or auto.

PIX Version 6.2(2)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
fixup protocol ftp 21
fixup protocol http 80
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol sip 5060
fixup protocol skinny 2000
pager lines 24
interface ethernet0 10full
interface ethernet1 10full
mtu outside 1500
mtu inside 1500
ip address outside dhcp setroute
ip address inside
ip audit info action alarm
ip audit attack action alarm
pdm logging informational 100
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0 0
static (inside,outside) tcp x.x.x.x pop3 pop3 netmask 255.255
.255.255 0 0
static (inside,outside) tcp x.x.x.x smtp smtp netmask 255.255
.255.255 0 0
static (inside,outside) tcp x.x.x.x www www netmask 255.255.2
55.255 0 0
static (inside,outside) tcp x.x.x.x 3389 3389 netmask 255.255
.255.255 0 0
static (inside,outside) tcp x.x.x.x https https netmask 255.2
55.255.255 0 0
static (inside,outside) tcp x.x.x.x 4125 4125 netmask 255.255
.255.255 0 0
static (inside,outside) tcp x.x.x.x ftp ftp netmask 255.255.2
55.255 0 0
static (inside,outside) tcp x.x.x.x 4899 4899 netmask 255.25
5.255.255 0 0
conduit permit tcp host x.x.x.x eq www any
conduit permit tcp host x.x.x.x eq 3389 any
conduit permit tcp host x.x.x.x eq smtp any
conduit permit tcp host x.x.x.x eq pop3 any
conduit permit tcp host x.x.x.x eq https any
conduit permit tcp host x.x.x.x eq 4125 any
conduit permit tcp host x.x.x.x eq ftp any
conduit permit tcp host x.x.x.x eq 4899 any
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si
p 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
http server enable
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
no sysopt route dnat
telnet timeout 5
ssh timeout 5
dhcpd auto_config outside
terminal width 80

Does anyone see anything wrong with this config?
Question by:plimpias
  • 2
LVL 79

Accepted Solution

lrmoore earned 125 total points
ID: 11940791
>PIX Version 6.2(2)
PIX OS 6.3(3) will give you 100Mb full duplex capability

>interface ethernet0 10full
>interface ethernet1 10full

If your switchport connected to Ethernet1 is not also set to 10/full you will have problems. If your switch is not managable and you can't set the speed/duplex, then leave the PIX interfaces at "auto"

   interface ethernet1 auto

Eventually, you will have to convert your conduits to access-lists.
LVL 15

Author Comment

ID: 11944027
My switch is not managable. however it is a GB switch. So your saying with 6.2 i can't do 100Full? unless i upgrade to 6.3?
LVL 79

Expert Comment

ID: 11944916
Correct. But you don't really need 100full because you're throttled at the other side to, what 2Mb?
The issue is that the switchport is set to autonegotiate, your PIX is set to 10full. Manually setting the duplex turns off the autonegotiation packet. If the switch does not receive an autonegotiation packet, it will most likely fall back to half-duplex. Now you have a duplex mismatch that is the culprit in your slowness..
From the PIX console, use "show interface" and look for collisions and error counts. If there are any errors, especially collisions, the problem will point to a duplex mismatch.

6.3(3) brought my 506 up to 100/full capability, but I'm only plugged into a 10Mb switch anyway.

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cisco MAC address finding 5 49
Command "logging persistent size .... " 6 28
Unblock a website in Cisco ASA 3 36
Cisco prime 3 22
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Cisco Pix/ASA hairpinning The term, hairpinning, comes from the fact that the traffic comes from one source into a router or similar device, makes a U-turn, and goes back the same way it came. Visualize this and you will see something that looks …
Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now