Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Cisco PIX and Gigabit

Thread Tools
 
Search this Thread
 
Old May 20, 2002 | 01:29 PM
  #1  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

Anyone ever experienced problmes with Cisco PIXes and Gigabit Interfaces (Fibre to Cat6500s and Cat4000s) ?

Seeing some very strange interface lock ups and other odd behaviour.

Deano
Reply
Old May 20, 2002 | 01:32 PM
  #2  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Cool

Wrong forum Deano
Reply
Old May 20, 2002 | 02:11 PM
  #3  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

Doh !
Reply
Old May 20, 2002 | 02:17 PM
  #4  
Scoobychick's Avatar
Scoobychick
Scooby Regular
iTrader: (1)
 
Joined: Feb 2001
Posts: 16,067
Likes: 1
From: Nobbering about...
Talking

S'ok I moved it
Reply
Old May 20, 2002 | 02:36 PM
  #5  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

There can't be many companies running Gigabit into PIX.....I guess that you've spoken to Cisco regarding the issue ?


Jeff
Reply
Old May 20, 2002 | 02:46 PM
  #6  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

Jeff

Its complicated. My infrastructure boundary is the Cat6500 Gig port. The pix and Cat4000 beyond is part of a managed service. Currently the guys looking after the PIXs seem reluctant to fully engage Cisco which is frustrating. (especially as the PIXs were part of a design done by a couple of Cisco SEs.)

Theres the usual finger pointing at each side of the boundary. but some of the problems are odd and unrepeatable. bouncing interfaces sometimes works - once or twice we've seen the PIX kernel panic and reload which cures it, other time reloads dont help.

Its all the more frustrating as we're not even putting 256K of traffic to them - let alone a gig

Juts wondering if anyone had played with the Gig interfaces before (not your home setup is it Jeff ?)

Deano

Reply
Old May 20, 2002 | 02:57 PM
  #7  
roadrunner's Avatar
roadrunner
Scooby Regular
 
Joined: May 2001
Posts: 730
Likes: 0
Post

Deano - I can talk to a CCIE security expert. Will need all the usual gumph though - revision, IOS, 6500 in Hybrid mode? etc etc etc

Reply
Old May 20, 2002 | 03:03 PM
  #8  
WillieF's Avatar
WillieF
Scooby Regular
 
Joined: Oct 1999
Posts: 778
Likes: 0
Talking

Gig fibre or gig copper?

Not much difference however I have had problems when the port has been left in Auto mode.

Reply
Old May 20, 2002 | 03:17 PM
  #9  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

All fibre - 6500 is in hybrid (CatOS on Sup, IOS on MSFC). 6500 least doesnt give the option for auto on the gig ports. (Seen no end if issues with auto ont he 10/100 ports).

On one occasion we appeared to be getting arps between MSFC and PIX but no IP. reloads, port resets had no affect. Changed GBICs etc (full scratching **** and change anything mode). 20 mins later PIX kernel panicked and reloaded - worked perfectly - to me thats as typical of a Cisco Bug as I've seen.

Damn things are only there to do NAT. the F/W is being done by Nokias further down.

My view is a TAC case should have been raised a month ago . We cant see anything on Bug tracker but we'll keep plugging away.

RR - You have CSPM

Deano
Reply
Old May 20, 2002 | 04:12 PM
  #10  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Damn expensive NAT solutions....

Its unlikely that you'll find an answer without getting a TAC case raised....I'm assuming that you have all the latest versions of code etc ?

I love the fact that you are using a 1 Gig PIX (Its the 535 ?) as a NAT device and then firewalling further down into (I assume) a cluster of IP730s.....and that the PIX 'panics'.....

Not much help I'm afraid


Jeff
Reply
Old May 20, 2002 | 04:24 PM
  #11  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

Jeff

Unfortunately Cisco were let loose with the spec sheets and design which was approved back in the midsts of time.

There are good reasons (historically our addressing is a "bag of ****") why we have to NAT separately. One "reason" for the PIXs was we could advertise our routes via RIP to save manual updates. Except the volume of RIP updates causes panics aswell so we had to turn it off.

I keep pushing for a TAC case but our "partner" is prevaricating.

Was really wondering if anyone else had seen Gig PIXs and ahd problems.

Reply
Old May 20, 2002 | 04:47 PM
  #12  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Well, I do think that the only people that will be able to help is Cisco themselves. You do appreciate that the Nokia boxes will do RIP/OSPF/BGP etc themselves (as well as NAT).

I'm not much help as the only devices that I've worked on with Gig (from a firewall perspective) are Netscreen 1000, Nokia IP730 and SonicWALL GX6500.....

Jeff
Reply
Old May 20, 2002 | 05:06 PM
  #13  
dsmith's Avatar
dsmith
Thread Starter
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Post

I know the nokias will do OSPF. I wanted to do OSPF to the Nokias but my TDA didn't - and there ended the discussion
Reply
Old May 20, 2002 | 05:12 PM
  #14  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Time to get a new TDA.........
Reply
Old May 21, 2002 | 09:05 AM
  #15  
SiCotty's Avatar
SiCotty
Scooby Regular
 
Joined: Jan 2001
Posts: 442
Likes: 0
Post

Are you using the latest version of the PIX software 6.2(1)? This is the first thing to try and the first thing TAC will suggest.

Si

[Edited by SiCotty - 5/21/2002 9:09:53 AM]
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
roadrunner
Non Scooby Related
7
Dec 14, 2001 12:19 PM
vmax
Non Scooby Related
2
Aug 24, 2001 07:53 PM
ownly
Member's Gallery
4
Apr 18, 2001 08:54 PM




All times are GMT +1. The time now is 01:39 AM.