• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 551
  • Last Modified:

Pix 515e

When I console in to the pix I get the following errors and I can't get into config mode because the errors continue to scroll. I kinda inherited this firewall because all IT personel left the company. Please assist me in getting connected to this PIX.

305005: No translation group found for tcp src inside:167.147.147.211/1380 dst o
utside:147.23.228.18/445
305005: No translation group found for tcp src inside:167.147.147.211/1382 dst o
utside:68.90.1.60/445
305005: No translation group found for tcp src inside:167.147.147.211/1381 dst o
utside:102.20.131.112/445
305005: No translation group found for tcp src inside:167.147.147.211/1417 dst o
utside:58.110.8.119/445
110001: No route to 167.147.147.254 from 167.147.146.1
305005: No translation group found for tcp src inside:167.147.147.68/1849 dst ou
tside:33.84.120.54/445
305005: No translation group found for tcp src inside:167.147.147.68/1850 dst ou
tside:50.79.115.13/445
305005: No translation group found for tcp src inside:167.147.147.68/1851 dst ou
tside:63.82.250.119/445
305005: No translation group found for tcp src inside:167.147.147.68/1852 dst ou
tside:186.107.18.101/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.211/1468 dst o
utside:103.52.186.41/445
305005: No translation group found for tcp src inside:167.147.147.211/1466 dst o
utside:50.3.200.33/445
305005: No translation group found for tcp src inside:167.147.147.211/1441 dst o
utside:38.5.92.60/445
305005: No translation group found for tcp src inside:167.147.147.211/1442 dst o
utside:41.88.144.57/445
305005: No translation group found for tcp src inside:167.147.147.211/1468 dst o
utside:103.52.186.41/445
305005: No translation group found for tcp src inside:167.147.147.211/1483 dst o
utside:56.86.215.35/445
305005: No translation group found for tcp src inside:167.147.147.211/1466 dst o
utside:50.3.200.33/445
305005: No translation group found for tcp src inside:167.147.147.211/1482 dst o
utside:113.17.199.4/445
305005: No translation group found for tcp src inside:167.147.147.211/1484 dst o
utside:109.37.48.124/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.67/3582 dst ou
tside:180.40.32.96/445
305005: No translation group found for tcp src inside:167.147.147.67/3583 dst ou
tside:157.32.164.37/445
305005: No translation group found for tcp src inside:167.147.147.67/3584 dst ou
tside:95.115.194.104/445
305005: No translation group found for tcp src inside:167.147.147.211/1538 dst o
utside:54.62.164.13/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.67/3616 dst ou
tside:169.67.92.103/445
305005: No translation group found for tcp src inside:167.147.147.67/3617 dst ou
tside:140.121.29.119/445
305005: No
0
betress
Asked:
betress
  • 5
  • 5
  • 4
2 Solutions
 
Ernie BeekExpertCommented:
Did you try accessing it through ASDM?
0
 
betressAuthor Commented:
I've tried to Telnet in, but it wont allow me to connect. Apparently someone set an ACL to their IP Address and I have no documention on the config of the firewall. Looks like I'm hosed.
0
 
Ernie BeekExpertCommented:
Well, you can just type through even when the errors are scrolling.

So try it:

- enable & password
-conf t
-no deb all
-no logg console

see if that helps.
0
KuppingerCole Reviews AlgoSec in Executive Report

Leading analyst firm, KuppingerCole reviews AlgoSec's Security Policy Management Solution, and the security challenges faced by companies today in their Executive View report.

 
pony10usCommented:
Something else you might try is download "putty" and see if you can connect with that.  

http://www.putty.org/

Connect with SSH instead of Telnet.

For security reasons most organizations will turn off telnet access.
0
 
betressAuthor Commented:
erniebeek, didn't work
0
 
betressAuthor Commented:
pony10us, I can't even ping the firewall all I can do is connect via console. Will Putty allow serial connection?
0
 
betressAuthor Commented:
pony10us, I connected with putty and it does the same thing.
0
 
pony10usCommented:
Can you type the commands that erniebeek gave you in the putty screen?  Watch closely for a response.
0
 
betressAuthor Commented:
I tried and I get nothing. It doesn't even pause.
0
 
Ernie BeekExpertCommented:
It might take some time for the buffer to flush. If you are sure the commands are entered correct,issue a wr mem and reload the pix. That might help.

If possible, just disconnect all network cables. that way the console won't be flooded with logging and you might be able to do some configuration.
0
 
pony10usCommented:
It sounds like you might have to access it durring off hours and unplug the interfaces so that the logging stops long enough for you to check the debug and logging levels. I would then get a good copy of the config stored off either on a thumb drive or tftp server and go through it very carefully.
0
 
Ernie BeekExpertCommented:
@pony10us: hehehehe, beat you to it ;)

But we are thinking the same way :)
0
 
pony10usCommented:
:)

I see that.  However you were a bit more thorough in mentioning the buffer needing to clear.  

0
 
Ernie BeekExpertCommented:
That's a matter of practice. But it looks like we solved the case though.
Good job!

And @betress: thx for the points :)
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Choose an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

  • 5
  • 5
  • 4
Tackle projects and never again get stuck behind a technical roadblock.
Join Now