Solved

Object-groups and Pix 525

Posted on 2006-11-16
11
407 Views
Last Modified: 2013-11-16
Hi

I have a 525 Pix with 256k of ram. Am using object-groups and turbo acls in my config because of the huge amount of ip addresses i have to enter. The config file is about 300k at the moment. While doing some more configuration last week, the Pix suddenly started rebooting and gave me this message while loading the config file: WARNING: access-list protocol or port will not be used.

I figured it might be a memory problem. So I blew the config away and started over again and reduced the # of static entries for the object-groups. It loaded ok with no messages. That was Tuesday. (The Pix is offline by the way). When I came in today (Thursday) and turned on the Pix I got the message again.

Can anyone tell me whats going on and how to address it?
0
Comment
Question by:mdelaine
  • 6
  • 5
11 Comments
 
LVL 20

Expert Comment

by:calvinetter
ID: 17958276
Are you by chance using a dash ('-') in an ACL name? If so, rename it using an underscore.  PIXes don't like '-' in ACL names.

cheers
0
 

Author Comment

by:mdelaine
ID: 17959617
Thought you might mention that. All my acl names have underscores in them. I have dashes in my object-group names ie: object-group network TEC-AC-MACHINES. I have not read anything to suggest this is a problem.
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17961146
I don't recall object group names themselves as causing a problem, but just to be safe, I'd try either modifying the object group or making a new one with underscores & see if that resolves it.  I'd suggest duplicating your existing ACL with the new object groups & give it a go.

cheers
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:mdelaine
ID: 17962463
Before I do that, I would like to add that this present config has been running all year with these particular compiled acls with no problem. My object-groups have been growing steadily and I was doing statics on a per host basis. The first time I even got this message was about 2 weeks ago when the pix started constantly rebooting after it stalled while I was loading a rather large list of static entries. Could not even get back into the pix until I pulled 1 of the memory cards out. At that time the Pix had about 15000 lines of code.

If you still want me to try, after this, I will.
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17966048
What specific PIX version are you running?  eg, 6.3(5)?
0
 

Author Comment

by:mdelaine
ID: 17967985
Version 6.3(3)
0
 

Author Comment

by:mdelaine
ID: 17968984
Can anyone tell me what "access-list protocol or port will not be used" means ?
0
 
LVL 20

Accepted Solution

by:
calvinetter earned 500 total points
ID: 17970373
6.3(3) ? That's quite a buggy version.  I strongly suggest upgrading to at least 6.3(5) ASAP if you have current SmartNet support on this PIX.
  Among the many bugs in your version:
CSCec64215 - Very large ACLs (>200K elements) may not compile, have very poor performance
CSCee24747 - High complexity ACLs may require excessively much memory
CSCed59572 - High CPU utilization with large static list

AFAIK, that warning message is just telling you that the PIX choked on 1 or more lines of the ACL due to names it doesn't like, etc or simply that the ACL didn't compile.

cheers
0
 

Author Comment

by:mdelaine
ID: 17972862
I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)

Do you think if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?

Will also recheck my access-lists for anything strange.

Will try Mon. 11/20
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17972899
>I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)
  If you mean you have access to a 6.3(4) image, & the PIX itself doesn't have a current SmartNet contract, you can't legally upgrade to 6.3(4).  Your PIX must have current SmartNet for you to qualify for newer versions of your software series.  Having said that, 6.3(4) fixes a ton of bugs in previous versions, notably the ones I posted earlier, plus *many* others.

>...if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?
   Not unless you suspect the entire ACL isn't getting complied.  If you run 'sh access-list' do you see "operational" in the State column next to your ACL name?

cheers
0
 

Author Comment

by:mdelaine
ID: 18078677
Obtained SmartNet for Pix. Upgraded IOS to VER 6.3(5). Reloaded full config. after optimising a bit and Pix works fine now. No error messages.

Thank you for your assistance.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco ASA IOS 9.x - no route to host for Internet 4 78
Palo Alto Networks: Truly No Hit Count? 2 45
Cisco WLAN 5520 licensing 10 37
Cisco  3750E switches 1 14
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question