Amanda-Users

FreeBSD, PIX, timeout strangeness.

2006-04-26 23:13:12
Subject: FreeBSD, PIX, timeout strangeness.
From: Matt <mnaismith AT gmail DOT com>
To: amanda-users AT amanda DOT org
Date: Thu, 27 Apr 2006 12:06:35 +1000

Hi,

I'm doing a nightly dump of a number of hosts on my network through a PIX firewall. Each morning i find the same hosts fail with the common "estimate timeout issue" which usually indicates a firewall problem. If i immediately run a dump of one of the failed hosts by itself it works fine ! Its only when i run a bunch together !   Could it be the PIX is not managing to keep state on all the traffic ?   I'm backing up FreeBSD hosts.. The interesting point is the FreeBSD6 servers never fail !

Here are some interesting differences in sysctl values..

FreeBSD4
net.inet.ip.portrange.first: 1024
net.inet.ip.portrange.last: 5000

FreeBSD6
net.inet.ip.portrange.first: 49152
net.inet.ip.portrange.last : 65535

I have tried adjusting the values but it doesn't seem to make any difference.. It possibly has absolutely nothing to do with it..

Some thoughts on this problem would be appreciated..

Matt.

<Prev in Thread] Current Thread [Next in Thread>