[fw-wiz] PIX 6.1 xlate issues



Hello there,
I am using a PIX 6.1 (I know its quite old and replacement procedures already in place) and facing problems with xlates getting
overwhelmed. I have this firewall serving our corporate network, where I have a proxy server, SMTP server, DNS server and about 1500 users
browsing the web through the proxy, along with other servers which I do static NAT on.

Overtime, my SMTP server loses connectivity with the DNS server (residing outside the firewall) for name resolution and the only
remedy to this is to clear the xlate. I've set the xlate timeout to as low as 30 mins, but the problem still persist.

Does anyone know of any resolution to this problem ?

Many thanks

Regards
Shiv
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • Re: Cant ping Just One Address
    ... I don't think that it's an address resolution issue as using both the server ... I mean that the ping times out. ... > Blocked pings generally have one cause - a misconfigured or overlooked firewall ...
    (microsoft.public.windowsxp.network_web)
  • Re: [fw-wiz] PIX 6.1 xlate issues
    ... I recently saw a PIX 515E become so overwhelmed with the number of NAT ... show xlate count, a log entry and the show mem output. ... have a proxy server, SMTP server, DNS server and about 1500 users ...
    (Firewall-Wizards)
  • Re: extremely strange issue, XP Pro - outbound connections work fine, inbound fail. No fire wall
    ... firewall installed. ... The oddest thing about this is not being able to ping it's IP but it's ... It can access file shares on a server, ... That's a name resolution issue. ...
    (microsoft.public.windowsxp.network_web)
  • Re: [fw-wiz] PIX 6.1 xlate issues
    ... but it involved the dns fixup. ... have a proxy server, SMTP server, DNS server and about 1500 users ... my SMTP server loses connectivity with the DNS server (residing ... remedy to this is to clear the xlate. ...
    (Firewall-Wizards)
  • Re: Change External IP Address on SBS2003
    ... How many nics in the SBS, and do you have a router / firewall between the server and the ISP endpoint. ... Please post the resolution to your ...
    (microsoft.public.windows.server.sbs)