Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Object-groups and Pix 525

Posted on 2006-11-16
11
Medium Priority
?
419 Views
Last Modified: 2013-11-16
Hi

I have a 525 Pix with 256k of ram. Am using object-groups and turbo acls in my config because of the huge amount of ip addresses i have to enter. The config file is about 300k at the moment. While doing some more configuration last week, the Pix suddenly started rebooting and gave me this message while loading the config file: WARNING: access-list protocol or port will not be used.

I figured it might be a memory problem. So I blew the config away and started over again and reduced the # of static entries for the object-groups. It loaded ok with no messages. That was Tuesday. (The Pix is offline by the way). When I came in today (Thursday) and turned on the Pix I got the message again.

Can anyone tell me whats going on and how to address it?
0
Comment
Question by:mdelaine
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
11 Comments
 
LVL 20

Expert Comment

by:calvinetter
ID: 17958276
Are you by chance using a dash ('-') in an ACL name? If so, rename it using an underscore.  PIXes don't like '-' in ACL names.

cheers
0
 

Author Comment

by:mdelaine
ID: 17959617
Thought you might mention that. All my acl names have underscores in them. I have dashes in my object-group names ie: object-group network TEC-AC-MACHINES. I have not read anything to suggest this is a problem.
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17961146
I don't recall object group names themselves as causing a problem, but just to be safe, I'd try either modifying the object group or making a new one with underscores & see if that resolves it.  I'd suggest duplicating your existing ACL with the new object groups & give it a go.

cheers
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:mdelaine
ID: 17962463
Before I do that, I would like to add that this present config has been running all year with these particular compiled acls with no problem. My object-groups have been growing steadily and I was doing statics on a per host basis. The first time I even got this message was about 2 weeks ago when the pix started constantly rebooting after it stalled while I was loading a rather large list of static entries. Could not even get back into the pix until I pulled 1 of the memory cards out. At that time the Pix had about 15000 lines of code.

If you still want me to try, after this, I will.
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17966048
What specific PIX version are you running?  eg, 6.3(5)?
0
 

Author Comment

by:mdelaine
ID: 17967985
Version 6.3(3)
0
 

Author Comment

by:mdelaine
ID: 17968984
Can anyone tell me what "access-list protocol or port will not be used" means ?
0
 
LVL 20

Accepted Solution

by:
calvinetter earned 2000 total points
ID: 17970373
6.3(3) ? That's quite a buggy version.  I strongly suggest upgrading to at least 6.3(5) ASAP if you have current SmartNet support on this PIX.
  Among the many bugs in your version:
CSCec64215 - Very large ACLs (>200K elements) may not compile, have very poor performance
CSCee24747 - High complexity ACLs may require excessively much memory
CSCed59572 - High CPU utilization with large static list

AFAIK, that warning message is just telling you that the PIX choked on 1 or more lines of the ACL due to names it doesn't like, etc or simply that the ACL didn't compile.

cheers
0
 

Author Comment

by:mdelaine
ID: 17972862
I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)

Do you think if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?

Will also recheck my access-lists for anything strange.

Will try Mon. 11/20
0
 
LVL 20

Expert Comment

by:calvinetter
ID: 17972899
>I have ver. 6.3(4)  Do not have SmartNet yet for 6.3(5)
  If you mean you have access to a 6.3(4) image, & the PIX itself doesn't have a current SmartNet contract, you can't legally upgrade to 6.3(4).  Your PIX must have current SmartNet for you to qualify for newer versions of your software series.  Having said that, 6.3(4) fixes a ton of bugs in previous versions, notably the ones I posted earlier, plus *many* others.

>...if I reduce the object-group lists and static lists by subnetting more, it might improve the performance ?
   Not unless you suspect the entire ACL isn't getting complied.  If you run 'sh access-list' do you see "operational" in the State column next to your ACL name?

cheers
0
 

Author Comment

by:mdelaine
ID: 18078677
Obtained SmartNet for Pix. Upgraded IOS to VER 6.3(5). Reloaded full config. after optimising a bit and Pix works fine now. No error messages.

Thank you for your assistance.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question