Solved

Object-groups and Pix 525

Posted on 2006-11-16
11
403 Views
Last Modified: 2013-11-16
Hi

I have a 525 Pix with 256k of ram. Am using object-groups and turbo acls in my config because of the huge amount of ip addresses i have to enter. The config file is about 300k at the moment. While doing some more configuration last week, the Pix suddenly started rebooting and gave me this message while loading the config file: WARNING: access-list protocol or port will not be used.

I figured it might be a memory problem. So I blew the config away and started over again and reduced the # of static entries for the object-groups. It loaded ok with no messages. That was Tuesday. (The Pix is offline by the way). When I came in today (Thursday) and turned on the Pix I got the message again.

Can anyone tell me whats going on and how to address it?
0
Comment
Question by:mdelaine
  • 6
  • 5
11 Comments
 
LVL 20

Expert Comment

by:calvinetter
Comment Utility
Are you by chance using a dash ('-') in an ACL name? If so, rename it using an underscore.  PIXes don't like '-' in ACL names.

cheers
0
 

Author Comment

by:mdelaine
Comment Utility
Thought you might mention that. All my acl names have underscores in them. I have dashes in my object-group names ie: object-group network TEC-AC-MACHINES. I have not read anything to suggest this is a problem.
0
 
LVL 20

Expert Comment

by:calvinetter
Comment Utility
I don't recall object group names themselves as causing a problem, but just to be safe, I'd try either modifying the object group or making a new one with underscores & see if that resolves it.  I'd suggest duplicating your existing ACL with the new object groups & give it a go.

cheers
0
 

Author Comment

by:mdelaine
Comment Utility
Before I do that, I would like to add that this present config has been running all year with these particular compiled acls with no problem. My object-groups have been growing steadily and I was doing statics on a per host basis. The first time I even got this message was about 2 weeks ago when the pix started constantly rebooting after it stalled while I was loading a rather large list of static entries. Could not even get back into the pix until I pulled 1 of the memory cards out. At that time the Pix had about 15000 lines of code.

If you still want me to try, after this, I will.
0
 
LVL 20

Expert Comment

by:calvinetter
Comment Utility
What specific PIX version are you running?  eg, 6.3(5)?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:mdelaine
Comment Utility
Version 6.3(3)
0
 

Author Comment

by:mdelaine
Comment Utility
Can anyone tell me what "access-list protocol or port will not be used" means ?
0
 
LVL 20

Accepted Solution

by:
calvinetter earned 500 total points
Comment Utility
6.3(3) ? That's quite a buggy version.  I strongly suggest upgrading to at least 6.3(5) ASAP if you have current SmartNet support on this PIX.
  Among the many bugs in your version:
CSCec64215 - Very large ACLs (>200K elements) may not compile, have very poor performance
CSCee24747 - High complexity ACLs may require excessively much memory
CSCed59572 - High CPU utilization with large static list

AFAIK, that warning message is just telling you that the PIX choked on 1 or more lines of the ACL due to names it doesn't like, etc or simply that the ACL didn't compile.

cheers
0
 

Author Comment

by:mdelaine
Comment Utility
I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)

Do you think if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?

Will also recheck my access-lists for anything strange.

Will try Mon. 11/20
0
 
LVL 20

Expert Comment

by:calvinetter
Comment Utility
>I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)
  If you mean you have access to a 6.3(4) image, & the PIX itself doesn't have a current SmartNet contract, you can't legally upgrade to 6.3(4).  Your PIX must have current SmartNet for you to qualify for newer versions of your software series.  Having said that, 6.3(4) fixes a ton of bugs in previous versions, notably the ones I posted earlier, plus *many* others.

>...if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?
   Not unless you suspect the entire ACL isn't getting complied.  If you run 'sh access-list' do you see "operational" in the State column next to your ACL name?

cheers
0
 

Author Comment

by:mdelaine
Comment Utility
Obtained SmartNet for Pix. Upgraded IOS to VER 6.3(5). Reloaded full config. after optimising a bit and Pix works fine now. No error messages.

Thank you for your assistance.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now