Re: [fw-wiz] PIX 6.1 xlate issues

this sounds odd. if it was an xlate issue with it getting overwhelmed
then not just the dns server but other devices would also have
connectivity issues. You should increase you logging level to
informational and see what the logs say when you encounter this issue.
I did have a similiar issue years ago (details are kind of hazy now)
but it involved the dns fixup. Try increasing your fixup to something
like 1024 since there shouldnt be a reason for dns packet to get
larger then this (fixup protocol dns maximum-length 1024) or just
disable dns fixup altogther and see if that resolves your issue. This
was due to the connection table filling up due to exchange making
abnormally large dns queries.


On Wed, Aug 20, 2008 at 2:02 AM, B Shivanthan <shivi@xxxxxxxxxxxxxx> wrote:
Hello there,
I am using a PIX 6.1 (I know its quite old and replacement procedures
already in place) and facing problems with xlates getting
overwhelmed. I have this firewall serving our corporate network, where I
have a proxy server, SMTP server, DNS server and about 1500 users
browsing the web through the proxy, along with other servers which I do
static NAT on.

Overtime, my SMTP server loses connectivity with the DNS server (residing
outside the firewall) for name resolution and the only
remedy to this is to clear the xlate. I've set the xlate timeout to as low
as 30 mins, but the problem still persist.

Does anyone know of any resolution to this problem ?

Many thanks


firewall-wizards mailing list

firewall-wizards mailing list

Relevant Pages

  • Re: Multiple server problems - HELP!
    ... DNS Suffix Search List...: name.local ... DHCP on server is to .254. ... SBS's LAN NIC case that DHCP server REALLLLLY should be the SBS server. ... Internet Connectivity ...
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... The name.local entries are used by my apache server to implement ... change button, more button, the "Primary DNS suffix of this ... Attr: subschemaSubentry ... Owner of the binding path: ...
  • Issues migrating SBS 2003 domain to Server 2008 Standard
    ... We are stuck migrating our SBS 2003 domain to Server 2008. ... Fatal Error:DsGetDcName (SRV-EXCH) call failed, ... Verify your Domain Name Sysytem (DNS) is ... network connectivity to a domain controller. ...
  • Re: DNS and msdcs
    ... It will work without the _msdcs zone, ... To what belongs "Still no connectivity"? ... Network browsing requires NetBios over TCP/IP as a minimum, if you have also subnets, you need WINS server in each subnet. ... DNS server from the NIC and add them as forwarders in the DNS ...
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... button, more button, the "Primary DNS suffix of this computer", it should ... The Security System could not establish a secured connection with the server ... Attr: subschemaSubentry ... Owner of the binding path: ...