Solved

Pix 515e

Posted on 2011-03-11
14
529 Views
Last Modified: 2012-05-11
When I console in to the pix I get the following errors and I can't get into config mode because the errors continue to scroll. I kinda inherited this firewall because all IT personel left the company. Please assist me in getting connected to this PIX.

305005: No translation group found for tcp src inside:167.147.147.211/1380 dst o
utside:147.23.228.18/445
305005: No translation group found for tcp src inside:167.147.147.211/1382 dst o
utside:68.90.1.60/445
305005: No translation group found for tcp src inside:167.147.147.211/1381 dst o
utside:102.20.131.112/445
305005: No translation group found for tcp src inside:167.147.147.211/1417 dst o
utside:58.110.8.119/445
110001: No route to 167.147.147.254 from 167.147.146.1
305005: No translation group found for tcp src inside:167.147.147.68/1849 dst ou
tside:33.84.120.54/445
305005: No translation group found for tcp src inside:167.147.147.68/1850 dst ou
tside:50.79.115.13/445
305005: No translation group found for tcp src inside:167.147.147.68/1851 dst ou
tside:63.82.250.119/445
305005: No translation group found for tcp src inside:167.147.147.68/1852 dst ou
tside:186.107.18.101/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.211/1468 dst o
utside:103.52.186.41/445
305005: No translation group found for tcp src inside:167.147.147.211/1466 dst o
utside:50.3.200.33/445
305005: No translation group found for tcp src inside:167.147.147.211/1441 dst o
utside:38.5.92.60/445
305005: No translation group found for tcp src inside:167.147.147.211/1442 dst o
utside:41.88.144.57/445
305005: No translation group found for tcp src inside:167.147.147.211/1468 dst o
utside:103.52.186.41/445
305005: No translation group found for tcp src inside:167.147.147.211/1483 dst o
utside:56.86.215.35/445
305005: No translation group found for tcp src inside:167.147.147.211/1466 dst o
utside:50.3.200.33/445
305005: No translation group found for tcp src inside:167.147.147.211/1482 dst o
utside:113.17.199.4/445
305005: No translation group found for tcp src inside:167.147.147.211/1484 dst o
utside:109.37.48.124/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.67/3582 dst ou
tside:180.40.32.96/445
305005: No translation group found for tcp src inside:167.147.147.67/3583 dst ou
tside:157.32.164.37/445
305005: No translation group found for tcp src inside:167.147.147.67/3584 dst ou
tside:95.115.194.104/445
305005: No translation group found for tcp src inside:167.147.147.211/1538 dst o
utside:54.62.164.13/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.67/3616 dst ou
tside:169.67.92.103/445
305005: No translation group found for tcp src inside:167.147.147.67/3617 dst ou
tside:140.121.29.119/445
305005: No
0
Comment
Question by:betress
  • 5
  • 5
  • 4
14 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
Did you try accessing it through ASDM?
0
 

Author Comment

by:betress
Comment Utility
I've tried to Telnet in, but it wont allow me to connect. Apparently someone set an ACL to their IP Address and I have no documention on the config of the firewall. Looks like I'm hosed.
0
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
Well, you can just type through even when the errors are scrolling.

So try it:

- enable & password
-conf t
-no deb all
-no logg console

see if that helps.
0
 
LVL 26

Expert Comment

by:pony10us
Comment Utility
Something else you might try is download "putty" and see if you can connect with that.  

http://www.putty.org/

Connect with SSH instead of Telnet.

For security reasons most organizations will turn off telnet access.
0
 

Author Comment

by:betress
Comment Utility
erniebeek, didn't work
0
 

Author Comment

by:betress
Comment Utility
pony10us, I can't even ping the firewall all I can do is connect via console. Will Putty allow serial connection?
0
 

Author Comment

by:betress
Comment Utility
pony10us, I connected with putty and it does the same thing.
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 26

Expert Comment

by:pony10us
Comment Utility
Can you type the commands that erniebeek gave you in the putty screen?  Watch closely for a response.
0
 

Author Comment

by:betress
Comment Utility
I tried and I get nothing. It doesn't even pause.
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 251 total points
Comment Utility
It might take some time for the buffer to flush. If you are sure the commands are entered correct,issue a wr mem and reload the pix. That might help.

If possible, just disconnect all network cables. that way the console won't be flooded with logging and you might be able to do some configuration.
0
 
LVL 26

Assisted Solution

by:pony10us
pony10us earned 249 total points
Comment Utility
It sounds like you might have to access it durring off hours and unplug the interfaces so that the logging stops long enough for you to check the debug and logging levels. I would then get a good copy of the config stored off either on a thumb drive or tftp server and go through it very carefully.
0
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
@pony10us: hehehehe, beat you to it ;)

But we are thinking the same way :)
0
 
LVL 26

Expert Comment

by:pony10us
Comment Utility
:)

I see that.  However you were a bit more thorough in mentioning the buffer needing to clear.  

0
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
That's a matter of practice. But it looks like we solved the case though.
Good job!

And @betress: thx for the points :)
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Suggested Solutions

Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now