Solved

ASA 5505 Stops Allowing traffic

Posted on 2010-11-15
4
461 Views
Last Modified: 2013-11-05
I have a new Cisco ASA 5505 firewall that I'm upgrading from an old Pix 506e I used the upgrade from pix to ASA tool that cisco has to get the new commands right and then manually input the commands when done everything works fine including VPN then a couple of hours will go by and then everything stops working I can't get traffic in or out. I actually wiped the firewall back to factory settings reconfigured the firewall and samething everything works fine for a few hours then nothing I have attached a copy of my running config any help would be appreciated,
config1115.txt
0
Comment
Question by:Bek364
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 17

Expert Comment

by:Kvistofta
ID: 34138796
I have reviewed your config and there is no config-errors in it that could possible be related to your problem with the ASA stops forwarding traffic after a while. The source of the error is either related to something else (ISP, LAN-switches?) or the ASA itself having a hardware issue.  I would recommend that you replace the unit and use the same config in another hardware.

/Kvistofta
0
 
LVL 9

Accepted Solution

by:
gavving earned 500 total points
ID: 34141595
Make sure that you're not having duplex mismatch issues.   I've seen many old PIX installations where the ports were hard coded for 100full or 10full or whatever.  Then when the ASA gets installed it's left on Auto, but the switches or ports you're plugging into are still hard coded.  Thus you get duplex mismatch errors.  These types of errors can cause the ASA to reset the interface and stop passing traffic.

Whats the output of a 'show int'?
0
 
LVL 8

Expert Comment

by:ShareefHuddle
ID: 34148029
Yes I agree. Either mismatch port settings or possibly MTU settings.
0
 

Author Comment

by:Bek364
ID: 34148291
@gavving
I noticed the dual settings for the ports as well when I was going through ever inch of this thing I had hard coded the vlan int for 100full but the actual int were still auto aut.o I changed them to match but I can't test to see if this resloves the issue until etiher the weekend or after 11:00pm, but I will post results after testing.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month6 days, 3 hours left to enroll

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question