Firebox X Edge (X15) locking up

Posted on 2006-05-25
Last Modified: 2008-02-01
I have a client with a Firebox X Edge, and every few hours or so the firewall just "locks up"  nobody can get out to the internet, and can't get to the configuration screen to look at the configuration until we do a hard reboot.

I've talked with Watchguard support guys, and they told me to watch the number of NAT connections and if that goes down to 0 the firewall will lock up (Which I'm not thrilled about that behavior).  Which I did and checked around for viruses, peer to peer programs etc that would be taking up connections all to no avail, it still locked up.

Next thing they are saying is to take the firewall back to factory defaults and reconfigure the whole thing back to the way it was because the configuration file may have become corrupt.  That I haven't done yet because I'm REALLY not looking forward to doing that.

Does anyone else have any other thoughts on what else could be causing this before I spend a saturday reconfiguring?

I'm having it log to a syslog server and don't see anything there going on before it locks up, it just stops.
It has one site to site VPN set up and 5 MUVPN clients that are used, not sure if that helps anyone.  

Any suggestions to troubleshoot would be very appreciated!
Question by:prima854
    LVL 9

    Accepted Solution

    Have you tried the firmware upgrade. I think the engineers are searching for an answer rather than knowing.
    The behaviour regarding the number of NAT connections is a standard reaction as the device considers this to be a DoS attack and so goes into Fail-Shut mode. Fail-shut is the default failure mode of the WatchGuard Firebox. This shuts down alll in/out traffic.

    An alternative to try is overheating? Does the box have enough ventilation and nothing is blocking the vents? Is it very hot at the time of crash? Are you logging environmental conditions?

    Hope this helps

    Author Comment

    Thanks Barny,
         Seems like a funny solution to DoS attacks, to shut down all traffic.  Isn't that what DoS attacks are trying to do?  Slow down/Stop traffic.  The solution seems the same as the problem.

        The firmware upgrade was one of the first thigns I tried, but still locks up.

         I've tried moving it away from all other sources of heat, but still no good.  Locks up randomly.  Unfortunately I'm not logging environmental conditions, so I can't give a difinitive "It's not overheating", but it doesn't seem THAT hot.

         I ended up going to factory defaults and reconfigured, and still the same behavior.  In further talking with Watchguard, they're sending out a replacement unit as I sat in front of the NAT Dump screen for two days watching all the connections and nothing significant ever went through it.

         Anyway, by default you get all the points, but I do appreciate the input, at least it gave me something to try!

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
    This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…
    Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    23 Experts available now in Live!

    Get 1:1 Help Now