Solved

Pix 515e

Posted on 2011-03-11
14
533 Views
Last Modified: 2012-05-11
When I console in to the pix I get the following errors and I can't get into config mode because the errors continue to scroll. I kinda inherited this firewall because all IT personel left the company. Please assist me in getting connected to this PIX.

305005: No translation group found for tcp src inside:167.147.147.211/1380 dst o
utside:147.23.228.18/445
305005: No translation group found for tcp src inside:167.147.147.211/1382 dst o
utside:68.90.1.60/445
305005: No translation group found for tcp src inside:167.147.147.211/1381 dst o
utside:102.20.131.112/445
305005: No translation group found for tcp src inside:167.147.147.211/1417 dst o
utside:58.110.8.119/445
110001: No route to 167.147.147.254 from 167.147.146.1
305005: No translation group found for tcp src inside:167.147.147.68/1849 dst ou
tside:33.84.120.54/445
305005: No translation group found for tcp src inside:167.147.147.68/1850 dst ou
tside:50.79.115.13/445
305005: No translation group found for tcp src inside:167.147.147.68/1851 dst ou
tside:63.82.250.119/445
305005: No translation group found for tcp src inside:167.147.147.68/1852 dst ou
tside:186.107.18.101/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.211/1468 dst o
utside:103.52.186.41/445
305005: No translation group found for tcp src inside:167.147.147.211/1466 dst o
utside:50.3.200.33/445
305005: No translation group found for tcp src inside:167.147.147.211/1441 dst o
utside:38.5.92.60/445
305005: No translation group found for tcp src inside:167.147.147.211/1442 dst o
utside:41.88.144.57/445
305005: No translation group found for tcp src inside:167.147.147.211/1468 dst o
utside:103.52.186.41/445
305005: No translation group found for tcp src inside:167.147.147.211/1483 dst o
utside:56.86.215.35/445
305005: No translation group found for tcp src inside:167.147.147.211/1466 dst o
utside:50.3.200.33/445
305005: No translation group found for tcp src inside:167.147.147.211/1482 dst o
utside:113.17.199.4/445
305005: No translation group found for tcp src inside:167.147.147.211/1484 dst o
utside:109.37.48.124/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.67/3582 dst ou
tside:180.40.32.96/445
305005: No translation group found for tcp src inside:167.147.147.67/3583 dst ou
tside:157.32.164.37/445
305005: No translation group found for tcp src inside:167.147.147.67/3584 dst ou
tside:95.115.194.104/445
305005: No translation group found for tcp src inside:167.147.147.211/1538 dst o
utside:54.62.164.13/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.67/3616 dst ou
tside:169.67.92.103/445
305005: No translation group found for tcp src inside:167.147.147.67/3617 dst ou
tside:140.121.29.119/445
305005: No
0
Comment
Question by:betress
  • 5
  • 5
  • 4
14 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35113074
Did you try accessing it through ASDM?
0
 

Author Comment

by:betress
ID: 35113103
I've tried to Telnet in, but it wont allow me to connect. Apparently someone set an ACL to their IP Address and I have no documention on the config of the firewall. Looks like I'm hosed.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35113122
Well, you can just type through even when the errors are scrolling.

So try it:

- enable & password
-conf t
-no deb all
-no logg console

see if that helps.
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 
LVL 26

Expert Comment

by:pony10us
ID: 35113156
Something else you might try is download "putty" and see if you can connect with that.  

http://www.putty.org/

Connect with SSH instead of Telnet.

For security reasons most organizations will turn off telnet access.
0
 

Author Comment

by:betress
ID: 35113164
erniebeek, didn't work
0
 

Author Comment

by:betress
ID: 35113189
pony10us, I can't even ping the firewall all I can do is connect via console. Will Putty allow serial connection?
0
 

Author Comment

by:betress
ID: 35113232
pony10us, I connected with putty and it does the same thing.
0
 
LVL 26

Expert Comment

by:pony10us
ID: 35113282
Can you type the commands that erniebeek gave you in the putty screen?  Watch closely for a response.
0
 

Author Comment

by:betress
ID: 35113297
I tried and I get nothing. It doesn't even pause.
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 251 total points
ID: 35113313
It might take some time for the buffer to flush. If you are sure the commands are entered correct,issue a wr mem and reload the pix. That might help.

If possible, just disconnect all network cables. that way the console won't be flooded with logging and you might be able to do some configuration.
0
 
LVL 26

Assisted Solution

by:pony10us
pony10us earned 249 total points
ID: 35113322
It sounds like you might have to access it durring off hours and unplug the interfaces so that the logging stops long enough for you to check the debug and logging levels. I would then get a good copy of the config stored off either on a thumb drive or tftp server and go through it very carefully.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35113328
@pony10us: hehehehe, beat you to it ;)

But we are thinking the same way :)
0
 
LVL 26

Expert Comment

by:pony10us
ID: 35113408
:)

I see that.  However you were a bit more thorough in mentioning the buffer needing to clear.  

0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35113480
That's a matter of practice. But it looks like we solved the case though.
Good job!

And @betress: thx for the points :)
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question