Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

RE: PIX 525 : pb with new TCP connections

Subject: RE: PIX 525 : pb with new TCP connections
Date: Sat, 22 Jan 2005 08:56:03 +0100
We have that problem in the both direction and several times a day!
Moreover, the problem don't occur for everybody at the same time.
Indeed, on a same subnet, one person can succeed in establishing new TCP 
connection while another can't.

Actually, symptoms didn't exist when we had just one 7301 (and then one PIX).
I don't know if it's important to analyse problem but I precise that we send 
packets through the both 7301 but our BGP neighbor send return packets through 
only one 7301.
I didn't remember the reason but it's like that!

Our IOS is : IOS (tm) 7301 Software (C7301-JK9S-M), Version 12.3(6), RELEASE 
SOFTWARE (fc3)

And to be exhaustive, I add that 2 Cisco 2950 are located between the 7301 and 
the PIX 525.

Gilles

-----Message d'origine-----
De : Andrew Shore [mailto:andrew.shore@holistecs.com] 
Envoyé : vendredi 21 janvier 2005 10 37 Delobel
À : Delobel Gilles (M.); firewalls@securityfocus.com
Objet : RE: PIX 525 : pb with new TCP connections

Which direction are you having problem making the connection?

Inside->out
Or
Outside->in

There was a bug in the PIX OS with connections from the outside->in if
the static statement as configured for PAT but I understood it to be
fixed in 6.3.4

Andy

-----Original Message-----
From: gilles delobel [mailto:gilles.delobel@polytechnique.fr] 
Sent: 20 January 2005 15:32
To: firewalls@securityfocus.com
Subject: PIX 525 : pb with new TCP connections



Hi,

We currently use 2 PIX 525 configuring for failover.
Outside interfaces are attached to 2 7300 Cisco Routers.
OSPF protocol is activated between the 4 appliances.
Version 6.3.4 is in use on the 2 PIX.
Our problem is that randomly, we can't succeed in establish new TCP
connections (it can last from few seconds to few minutes).
At the same time, Ping or Traceroute work correctly.
We had reboot the both PIX without success.

Any ideas ??



<Prev in Thread] Current Thread [Next in Thread>