Solved

Object-groups and Pix 525

Posted on 2006-11-16
11
405 Views
Last Modified: 2013-11-16
Hi

I have a 525 Pix with 256k of ram. Am using object-groups and turbo acls in my config because of the huge amount of ip addresses i have to enter. The config file is about 300k at the moment. While doing some more configuration last week, the Pix suddenly started rebooting and gave me this message while loading the config file: WARNING: access-list protocol or port will not be used.

I figured it might be a memory problem. So I blew the config away and started over again and reduced the # of static entries for the object-groups. It loaded ok with no messages. That was Tuesday. (The Pix is offline by the way). When I came in today (Thursday) and turned on the Pix I got the message again.

Can anyone tell me whats going on and how to address it?
0
Comment
Question by:mdelaine
  • 6
  • 5
11 Comments
 
LVL 20

Expert Comment

by:calvinetter
ID: 17958276
Are you by chance using a dash ('-') in an ACL name? If so, rename it using an underscore.  PIXes don't like '-' in ACL names.

cheers
0
 

Author Comment

by:mdelaine
ID: 17959617
Thought you might mention that. All my acl names have underscores in them. I have dashes in my object-group names ie: object-group network TEC-AC-MACHINES. I have not read anything to suggest this is a problem.
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17961146
I don't recall object group names themselves as causing a problem, but just to be safe, I'd try either modifying the object group or making a new one with underscores & see if that resolves it.  I'd suggest duplicating your existing ACL with the new object groups & give it a go.

cheers
0
 

Author Comment

by:mdelaine
ID: 17962463
Before I do that, I would like to add that this present config has been running all year with these particular compiled acls with no problem. My object-groups have been growing steadily and I was doing statics on a per host basis. The first time I even got this message was about 2 weeks ago when the pix started constantly rebooting after it stalled while I was loading a rather large list of static entries. Could not even get back into the pix until I pulled 1 of the memory cards out. At that time the Pix had about 15000 lines of code.

If you still want me to try, after this, I will.
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17966048
What specific PIX version are you running?  eg, 6.3(5)?
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:mdelaine
ID: 17967985
Version 6.3(3)
0
 

Author Comment

by:mdelaine
ID: 17968984
Can anyone tell me what "access-list protocol or port will not be used" means ?
0
 
LVL 20

Accepted Solution

by:
calvinetter earned 500 total points
ID: 17970373
6.3(3) ? That's quite a buggy version.  I strongly suggest upgrading to at least 6.3(5) ASAP if you have current SmartNet support on this PIX.
  Among the many bugs in your version:
CSCec64215 - Very large ACLs (>200K elements) may not compile, have very poor performance
CSCee24747 - High complexity ACLs may require excessively much memory
CSCed59572 - High CPU utilization with large static list

AFAIK, that warning message is just telling you that the PIX choked on 1 or more lines of the ACL due to names it doesn't like, etc or simply that the ACL didn't compile.

cheers
0
 

Author Comment

by:mdelaine
ID: 17972862
I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)

Do you think if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?

Will also recheck my access-lists for anything strange.

Will try Mon. 11/20
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17972899
>I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)
  If you mean you have access to a 6.3(4) image, & the PIX itself doesn't have a current SmartNet contract, you can't legally upgrade to 6.3(4).  Your PIX must have current SmartNet for you to qualify for newer versions of your software series.  Having said that, 6.3(4) fixes a ton of bugs in previous versions, notably the ones I posted earlier, plus *many* others.

>...if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?
   Not unless you suspect the entire ACL isn't getting complied.  If you run 'sh access-list' do you see "operational" in the State column next to your ACL name?

cheers
0
 

Author Comment

by:mdelaine
ID: 18078677
Obtained SmartNet for Pix. Upgraded IOS to VER 6.3(5). Reloaded full config. after optimising a bit and Pix works fine now. No error messages.

Thank you for your assistance.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are many useful and sometimes not well documented or forgotten IOS or ASA/PIX commands. See IPE article here , there was also one on PacketU and on Cisco Tips & Tricks. Below are my favorites. I give also a few most often used for Cisco IPS an…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Need to grow your business through quality cloud solutions? With everything required to build a cloud platform and solution, you may feel like the distance between you and the cloud is quite long. Help is here. Spend some time learning about the Con…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now