Solved

Object-groups and Pix 525

Posted on 2006-11-16
11
411 Views
Last Modified: 2013-11-16
Hi

I have a 525 Pix with 256k of ram. Am using object-groups and turbo acls in my config because of the huge amount of ip addresses i have to enter. The config file is about 300k at the moment. While doing some more configuration last week, the Pix suddenly started rebooting and gave me this message while loading the config file: WARNING: access-list protocol or port will not be used.

I figured it might be a memory problem. So I blew the config away and started over again and reduced the # of static entries for the object-groups. It loaded ok with no messages. That was Tuesday. (The Pix is offline by the way). When I came in today (Thursday) and turned on the Pix I got the message again.

Can anyone tell me whats going on and how to address it?
0
Comment
Question by:mdelaine
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
11 Comments
 
LVL 20

Expert Comment

by:calvinetter
ID: 17958276
Are you by chance using a dash ('-') in an ACL name? If so, rename it using an underscore.  PIXes don't like '-' in ACL names.

cheers
0
 

Author Comment

by:mdelaine
ID: 17959617
Thought you might mention that. All my acl names have underscores in them. I have dashes in my object-group names ie: object-group network TEC-AC-MACHINES. I have not read anything to suggest this is a problem.
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17961146
I don't recall object group names themselves as causing a problem, but just to be safe, I'd try either modifying the object group or making a new one with underscores & see if that resolves it.  I'd suggest duplicating your existing ACL with the new object groups & give it a go.

cheers
0
How our DevOps Teams Maximize Uptime

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us. Read the use case whitepaper.

 

Author Comment

by:mdelaine
ID: 17962463
Before I do that, I would like to add that this present config has been running all year with these particular compiled acls with no problem. My object-groups have been growing steadily and I was doing statics on a per host basis. The first time I even got this message was about 2 weeks ago when the pix started constantly rebooting after it stalled while I was loading a rather large list of static entries. Could not even get back into the pix until I pulled 1 of the memory cards out. At that time the Pix had about 15000 lines of code.

If you still want me to try, after this, I will.
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17966048
What specific PIX version are you running?  eg, 6.3(5)?
0
 

Author Comment

by:mdelaine
ID: 17967985
Version 6.3(3)
0
 

Author Comment

by:mdelaine
ID: 17968984
Can anyone tell me what "access-list protocol or port will not be used" means ?
0
 
LVL 20

Accepted Solution

by:
calvinetter earned 500 total points
ID: 17970373
6.3(3) ? That's quite a buggy version.  I strongly suggest upgrading to at least 6.3(5) ASAP if you have current SmartNet support on this PIX.
  Among the many bugs in your version:
CSCec64215 - Very large ACLs (>200K elements) may not compile, have very poor performance
CSCee24747 - High complexity ACLs may require excessively much memory
CSCed59572 - High CPU utilization with large static list

AFAIK, that warning message is just telling you that the PIX choked on 1 or more lines of the ACL due to names it doesn't like, etc or simply that the ACL didn't compile.

cheers
0
 

Author Comment

by:mdelaine
ID: 17972862
I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)

Do you think if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?

Will also recheck my access-lists for anything strange.

Will try Mon. 11/20
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17972899
>I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)
  If you mean you have access to a 6.3(4) image, & the PIX itself doesn't have a current SmartNet contract, you can't legally upgrade to 6.3(4).  Your PIX must have current SmartNet for you to qualify for newer versions of your software series.  Having said that, 6.3(4) fixes a ton of bugs in previous versions, notably the ones I posted earlier, plus *many* others.

>...if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?
   Not unless you suspect the entire ACL isn't getting complied.  If you run 'sh access-list' do you see "operational" in the State column next to your ACL name?

cheers
0
 

Author Comment

by:mdelaine
ID: 18078677
Obtained SmartNet for Pix. Upgraded IOS to VER 6.3(5). Reloaded full config. after optimising a bit and Pix works fine now. No error messages.

Thank you for your assistance.
0

Featured Post

Retailers - Is your network secure?

With the prevalence of social media & networking tools, for retailers, reputation is critical. Have you considered the impact your network security could have in your customer's experience? Learn more in our Retail Security Resource Kit Today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question