Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Cisco PIX and Gigabit

Thread Tools
 
Search this Thread
 
Old 20 May 2002, 01:29 PM
  #1  
dsmith
Scooby Regular
Thread Starter
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

Anyone ever experienced problmes with Cisco PIXes and Gigabit Interfaces (Fibre to Cat6500s and Cat4000s) ?

Seeing some very strange interface lock ups and other odd behaviour.

Deano
Old 20 May 2002, 01:32 PM
  #2  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Cool

Wrong forum Deano
Old 20 May 2002, 02:11 PM
  #3  
dsmith
Scooby Regular
Thread Starter
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

Doh !
Old 20 May 2002, 02:17 PM
  #4  
Scoobychick
Scooby Regular
iTrader: (1)
 
Scoobychick's Avatar
 
Join Date: Feb 2001
Location: Nobbering about...
Posts: 16,067
Likes: 0
Received 0 Likes on 0 Posts
Talking

S'ok I moved it
Old 20 May 2002, 02:36 PM
  #5  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

There can't be many companies running Gigabit into PIX.....I guess that you've spoken to Cisco regarding the issue ?


Jeff
Old 20 May 2002, 02:46 PM
  #6  
dsmith
Scooby Regular
Thread Starter
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

Jeff

Its complicated. My infrastructure boundary is the Cat6500 Gig port. The pix and Cat4000 beyond is part of a managed service. Currently the guys looking after the PIXs seem reluctant to fully engage Cisco which is frustrating. (especially as the PIXs were part of a design done by a couple of Cisco SEs.)

Theres the usual finger pointing at each side of the boundary. but some of the problems are odd and unrepeatable. bouncing interfaces sometimes works - once or twice we've seen the PIX kernel panic and reload which cures it, other time reloads dont help.

Its all the more frustrating as we're not even putting 256K of traffic to them - let alone a gig

Juts wondering if anyone had played with the Gig interfaces before (not your home setup is it Jeff ?)

Deano

Old 20 May 2002, 02:57 PM
  #7  
roadrunner
Scooby Regular
 
roadrunner's Avatar
 
Join Date: May 2001
Posts: 730
Likes: 0
Received 0 Likes on 0 Posts
Post

Deano - I can talk to a CCIE security expert. Will need all the usual gumph though - revision, IOS, 6500 in Hybrid mode? etc etc etc


Trending Topics

Old 20 May 2002, 03:03 PM
  #8  
WillieF
Scooby Regular
 
WillieF's Avatar
 
Join Date: Oct 1999
Posts: 778
Likes: 0
Received 0 Likes on 0 Posts
Talking

Gig fibre or gig copper?

Not much difference however I have had problems when the port has been left in Auto mode.

Old 20 May 2002, 03:17 PM
  #9  
dsmith
Scooby Regular
Thread Starter
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

All fibre - 6500 is in hybrid (CatOS on Sup, IOS on MSFC). 6500 least doesnt give the option for auto on the gig ports. (Seen no end if issues with auto ont he 10/100 ports).

On one occasion we appeared to be getting arps between MSFC and PIX but no IP. reloads, port resets had no affect. Changed GBICs etc (full scratching **** and change anything mode). 20 mins later PIX kernel panicked and reloaded - worked perfectly - to me thats as typical of a Cisco Bug as I've seen.

Damn things are only there to do NAT. the F/W is being done by Nokias further down.

My view is a TAC case should have been raised a month ago . We cant see anything on Bug tracker but we'll keep plugging away.

RR - You have CSPM

Deano
Old 20 May 2002, 04:12 PM
  #10  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Damn expensive NAT solutions....

Its unlikely that you'll find an answer without getting a TAC case raised....I'm assuming that you have all the latest versions of code etc ?

I love the fact that you are using a 1 Gig PIX (Its the 535 ?) as a NAT device and then firewalling further down into (I assume) a cluster of IP730s.....and that the PIX 'panics'.....

Not much help I'm afraid


Jeff
Old 20 May 2002, 04:24 PM
  #11  
dsmith
Scooby Regular
Thread Starter
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

Jeff

Unfortunately Cisco were let loose with the spec sheets and design which was approved back in the midsts of time.

There are good reasons (historically our addressing is a "bag of ****") why we have to NAT separately. One "reason" for the PIXs was we could advertise our routes via RIP to save manual updates. Except the volume of RIP updates causes panics aswell so we had to turn it off.

I keep pushing for a TAC case but our "partner" is prevaricating.

Was really wondering if anyone else had seen Gig PIXs and ahd problems.

Old 20 May 2002, 04:47 PM
  #12  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Well, I do think that the only people that will be able to help is Cisco themselves. You do appreciate that the Nokia boxes will do RIP/OSPF/BGP etc themselves (as well as NAT).

I'm not much help as the only devices that I've worked on with Gig (from a firewall perspective) are Netscreen 1000, Nokia IP730 and SonicWALL GX6500.....

Jeff
Old 20 May 2002, 05:06 PM
  #13  
dsmith
Scooby Regular
Thread Starter
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

I know the nokias will do OSPF. I wanted to do OSPF to the Nokias but my TDA didn't - and there ended the discussion
Old 20 May 2002, 05:12 PM
  #14  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Time to get a new TDA.........
Old 21 May 2002, 09:05 AM
  #15  
SiCotty
Scooby Regular
 
SiCotty's Avatar
 
Join Date: Jan 2001
Posts: 442
Likes: 0
Received 0 Likes on 0 Posts
Post

Are you using the latest version of the PIX software 6.2(1)? This is the first thing to try and the first thing TAC will suggest.

Si

[Edited by SiCotty - 5/21/2002 9:09:53 AM]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
roadrunner
Non Scooby Related
7
14 December 2001 12:19 PM
vmax
Non Scooby Related
2
24 August 2001 07:53 PM
ownly
Member's Gallery
4
18 April 2001 08:54 PM



Quick Reply: Cisco PIX and Gigabit



All times are GMT +1. The time now is 09:59 AM.