FreeBSD, PIX, timeout strangeness.
2006-04-26 23:13:12
Hi,
I'm doing a nightly dump of a number of hosts on my network through a PIX firewall. Each morning i find the same hosts fail with the common "estimate timeout issue" which usually indicates a firewall problem. If i immediately run a dump of one of the failed hosts by itself it works fine ! Its only when i run a bunch together ! Could it be the PIX is not managing to keep state on all the traffic ? I'm backing up FreeBSD hosts.. The interesting point is the FreeBSD6 servers never fail !
Here are some interesting differences in sysctl values..
FreeBSD4 net.inet.ip.portrange.first: 1024 net.inet.ip.portrange.last: 5000
FreeBSD6 net.inet.ip.portrange.first: 49152 net.inet.ip.portrange.last
: 65535
I have tried adjusting the values but it doesn't seem to make any difference.. It possibly has absolutely nothing to do with it..
Some thoughts on this problem would be appreciated..
Matt.
|
<Prev in Thread] |
Current Thread |
[Next in Thread>
|
- FreeBSD, PIX, timeout strangeness.,
Matt <=
|
|
|