Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


PIX 506 Duplex speed change

Posted on 2004-08-30
Medium Priority
Last Modified: 2007-12-19
I want to change the internal interface speed. For some reason my download speed has decreased to 70 Kbps. I have reset the pix a few times and reset the modem, the switch is new. I want to change the duplex speed on my internal interface. but it says..
ethernet1 can only be set to 10baseT, 10full or auto.

PIX Version 6.2(2)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
fixup protocol ftp 21
fixup protocol http 80
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol sip 5060
fixup protocol skinny 2000
pager lines 24
interface ethernet0 10full
interface ethernet1 10full
mtu outside 1500
mtu inside 1500
ip address outside dhcp setroute
ip address inside
ip audit info action alarm
ip audit attack action alarm
pdm logging informational 100
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0 0
static (inside,outside) tcp x.x.x.x pop3 pop3 netmask 255.255
.255.255 0 0
static (inside,outside) tcp x.x.x.x smtp smtp netmask 255.255
.255.255 0 0
static (inside,outside) tcp x.x.x.x www www netmask 255.255.2
55.255 0 0
static (inside,outside) tcp x.x.x.x 3389 3389 netmask 255.255
.255.255 0 0
static (inside,outside) tcp x.x.x.x https https netmask 255.2
55.255.255 0 0
static (inside,outside) tcp x.x.x.x 4125 4125 netmask 255.255
.255.255 0 0
static (inside,outside) tcp x.x.x.x ftp ftp netmask 255.255.2
55.255 0 0
static (inside,outside) tcp x.x.x.x 4899 4899 netmask 255.25
5.255.255 0 0
conduit permit tcp host x.x.x.x eq www any
conduit permit tcp host x.x.x.x eq 3389 any
conduit permit tcp host x.x.x.x eq smtp any
conduit permit tcp host x.x.x.x eq pop3 any
conduit permit tcp host x.x.x.x eq https any
conduit permit tcp host x.x.x.x eq 4125 any
conduit permit tcp host x.x.x.x eq ftp any
conduit permit tcp host x.x.x.x eq 4899 any
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si
p 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
http server enable
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
no sysopt route dnat
telnet timeout 5
ssh timeout 5
dhcpd auto_config outside
terminal width 80

Does anyone see anything wrong with this config?
Question by:plimpias
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
LVL 79

Accepted Solution

lrmoore earned 375 total points
ID: 11940791
>PIX Version 6.2(2)
PIX OS 6.3(3) will give you 100Mb full duplex capability

>interface ethernet0 10full
>interface ethernet1 10full

If your switchport connected to Ethernet1 is not also set to 10/full you will have problems. If your switch is not managable and you can't set the speed/duplex, then leave the PIX interfaces at "auto"

   interface ethernet1 auto

Eventually, you will have to convert your conduits to access-lists.
LVL 15

Author Comment

ID: 11944027
My switch is not managable. however it is a GB switch. So your saying with 6.2 i can't do 100Full? unless i upgrade to 6.3?
LVL 79

Expert Comment

ID: 11944916
Correct. But you don't really need 100full because you're throttled at the other side to, what 2Mb?
The issue is that the switchport is set to autonegotiate, your PIX is set to 10full. Manually setting the duplex turns off the autonegotiation packet. If the switch does not receive an autonegotiation packet, it will most likely fall back to half-duplex. Now you have a duplex mismatch that is the culprit in your slowness..
From the PIX console, use "show interface" and look for collisions and error counts. If there are any errors, especially collisions, the problem will point to a duplex mismatch.

6.3(3) brought my 506 up to 100/full capability, but I'm only plugged into a 10Mb switch anyway.

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question