Solved

Pix 515e

Posted on 2011-03-11
14
532 Views
Last Modified: 2012-05-11
When I console in to the pix I get the following errors and I can't get into config mode because the errors continue to scroll. I kinda inherited this firewall because all IT personel left the company. Please assist me in getting connected to this PIX.

305005: No translation group found for tcp src inside:167.147.147.211/1380 dst o
utside:147.23.228.18/445
305005: No translation group found for tcp src inside:167.147.147.211/1382 dst o
utside:68.90.1.60/445
305005: No translation group found for tcp src inside:167.147.147.211/1381 dst o
utside:102.20.131.112/445
305005: No translation group found for tcp src inside:167.147.147.211/1417 dst o
utside:58.110.8.119/445
110001: No route to 167.147.147.254 from 167.147.146.1
305005: No translation group found for tcp src inside:167.147.147.68/1849 dst ou
tside:33.84.120.54/445
305005: No translation group found for tcp src inside:167.147.147.68/1850 dst ou
tside:50.79.115.13/445
305005: No translation group found for tcp src inside:167.147.147.68/1851 dst ou
tside:63.82.250.119/445
305005: No translation group found for tcp src inside:167.147.147.68/1852 dst ou
tside:186.107.18.101/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.211/1468 dst o
utside:103.52.186.41/445
305005: No translation group found for tcp src inside:167.147.147.211/1466 dst o
utside:50.3.200.33/445
305005: No translation group found for tcp src inside:167.147.147.211/1441 dst o
utside:38.5.92.60/445
305005: No translation group found for tcp src inside:167.147.147.211/1442 dst o
utside:41.88.144.57/445
305005: No translation group found for tcp src inside:167.147.147.211/1468 dst o
utside:103.52.186.41/445
305005: No translation group found for tcp src inside:167.147.147.211/1483 dst o
utside:56.86.215.35/445
305005: No translation group found for tcp src inside:167.147.147.211/1466 dst o
utside:50.3.200.33/445
305005: No translation group found for tcp src inside:167.147.147.211/1482 dst o
utside:113.17.199.4/445
305005: No translation group found for tcp src inside:167.147.147.211/1484 dst o
utside:109.37.48.124/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.67/3582 dst ou
tside:180.40.32.96/445
305005: No translation group found for tcp src inside:167.147.147.67/3583 dst ou
tside:157.32.164.37/445
305005: No translation group found for tcp src inside:167.147.147.67/3584 dst ou
tside:95.115.194.104/445
305005: No translation group found for tcp src inside:167.147.147.211/1538 dst o
utside:54.62.164.13/445
313001: Denied ICMP type=5, code=0 from 167.147.146.3 on interface 1
305005: No translation group found for tcp src inside:167.147.147.67/3616 dst ou
tside:169.67.92.103/445
305005: No translation group found for tcp src inside:167.147.147.67/3617 dst ou
tside:140.121.29.119/445
305005: No
0
Comment
Question by:betress
  • 5
  • 5
  • 4
14 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35113074
Did you try accessing it through ASDM?
0
 

Author Comment

by:betress
ID: 35113103
I've tried to Telnet in, but it wont allow me to connect. Apparently someone set an ACL to their IP Address and I have no documention on the config of the firewall. Looks like I'm hosed.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35113122
Well, you can just type through even when the errors are scrolling.

So try it:

- enable & password
-conf t
-no deb all
-no logg console

see if that helps.
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 
LVL 26

Expert Comment

by:pony10us
ID: 35113156
Something else you might try is download "putty" and see if you can connect with that.  

http://www.putty.org/

Connect with SSH instead of Telnet.

For security reasons most organizations will turn off telnet access.
0
 

Author Comment

by:betress
ID: 35113164
erniebeek, didn't work
0
 

Author Comment

by:betress
ID: 35113189
pony10us, I can't even ping the firewall all I can do is connect via console. Will Putty allow serial connection?
0
 

Author Comment

by:betress
ID: 35113232
pony10us, I connected with putty and it does the same thing.
0
 
LVL 26

Expert Comment

by:pony10us
ID: 35113282
Can you type the commands that erniebeek gave you in the putty screen?  Watch closely for a response.
0
 

Author Comment

by:betress
ID: 35113297
I tried and I get nothing. It doesn't even pause.
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 251 total points
ID: 35113313
It might take some time for the buffer to flush. If you are sure the commands are entered correct,issue a wr mem and reload the pix. That might help.

If possible, just disconnect all network cables. that way the console won't be flooded with logging and you might be able to do some configuration.
0
 
LVL 26

Assisted Solution

by:pony10us
pony10us earned 249 total points
ID: 35113322
It sounds like you might have to access it durring off hours and unplug the interfaces so that the logging stops long enough for you to check the debug and logging levels. I would then get a good copy of the config stored off either on a thumb drive or tftp server and go through it very carefully.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35113328
@pony10us: hehehehe, beat you to it ;)

But we are thinking the same way :)
0
 
LVL 26

Expert Comment

by:pony10us
ID: 35113408
:)

I see that.  However you were a bit more thorough in mentioning the buffer needing to clear.  

0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35113480
That's a matter of practice. But it looks like we solved the case though.
Good job!

And @betress: thx for the points :)
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

792 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question