I am having problems with my Pix, it goes offline for a short perior, plus get bad ftp performance with it. I have 6 interfaces outside, and
5 vlan interfaces on the inside, I have all the NAT's built. Not sure if there is something I am doing incorrect. I have 4 more PIX's and am probably going to upgrade to 7.0 but will have to relearn the pix in the new commands.Any help would be greatly appreciated
My firewall config is as follows:
dimepix1> en Password: ****** dimepix1# show run : Saved : PIX Version 6.3(5) interface ethernet0 100full interface ethernet1 100full interface ethernet1 vlan35 physical interface ethernet1 vlan20 logical interface ethernet1 vlan21 logical interface ethernet1 vlan22 logical interface ethernet1 vlan23 logical nameif ethernet0 outside security0 nameif ethernet1 inside security100 nameif vlan20 priv security96 nameif vlan21 reggie security99 nameif vlan22 net3 security98 nameif vlan23 net4 security97 hostname dimepix1 fixup protocol dns maximum-length 512 fixup protocol ftp 21 fixup protocol h323 h225 1720 fixup protocol h323 ras 1718-1719 fixup protocol http 80 fixup protocol rsh 514 fixup protocol rtsp 554 fixup protocol sip 5060 fixup protocol sip udp 5060 fixup protocol skinny 2000 no fixup protocol smtp 25 fixup protocol sqlnet 1521 fixup protocol tftp 69 names access-list 101 permit ip 72.29.91.64 255.255.255.240 any access-list 101 permit ip 72.29.91.80 255.255.255.240 any access-list 101 permit ip 72.29.91.96 255.255.255.240 any access-list 101 permit ip 72.29.91.112 255.255.255.248 any pager lines 24 mtu outside 1500 mtu inside 1500 ip address outside 72.29.91.125 255.255.255.248 no ip address inside ip address priv 72.29.91.65 255.255.255.240 ip address reggie 72.29.91.81 255.255.255.240 ip address net3 72.29.91.97 255.255.255.240 ip address net4 72.29.91.113 255.255.255.248 ip audit info action alarm ip audit attack action alarm no failover failover timeout 0:00:00 failover poll 15 no failover ip address outside no failover ip address inside no failover ip address priv no failover ip address reggie no failover ip address net3 no failover ip address net4 pdm history enable arp timeout 14400 nat (inside) 0 72.29.91.64 255.255.255.240 0 0 nat (reggie) 0 72.29.91.80 255.255.255.240 0 0 nat (net3) 0 72.29.91.96 255.255.255.240 0 0 nat (net4) 0 72.29.91.112 255.255.255.248 0 0 static (reggie,outside) 72.29.91.84 72.29.91.84 netmask 255.255.255.255
0 0 static (reggie,outside) 72.29.91.83 72.29.91.83 netmask 255.255.255.255 0 0 static (reggie,outside) 72.29.91.82 72.29.91.82 netmask 255.255.255.255 0 0 static (reggie,outside) 72.29.91.85 72.29.91.85 netmask 255.255.255.255 0 0 static (reggie,outside) 72.29.91.86 72.29.91.86 netmask 255.255.255.255 0 0 static (reggie,outside) 72.29.91.87 72.29.91.87 netmask 255.255.255.255 0 0 static (reggie,outside) 72.29.91.88 72.29.91.88 netmask 255.255.255.255 0 0 static (reggie,outside) 72.29.91.89 72.29.91.89 netmask 255.255.255.255 0 0 static (reggie,outside) 72.29.91.94 72.29.91.94 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.98 72.29.91.98 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.99 72.29.91.99 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.100 72.29.91.100 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.101 72.29.91.101 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.102 72.29.91.102 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.103 72.29.91.103 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.104 72.29.91.104 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.105 72.29.91.105 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.106 72.29.91.106 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.107 72.29.91.107 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.108 72.29.91.108 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.109 72.29.91.109 netmask 255.255.255.255 0 0 static (net3,outside) 72.29.91.110 72.29.91.110 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.66 72.29.91.66 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.67 72.29.91.67 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.68 72.29.91.68 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.69 72.29.91.69 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.70 72.29.91.70 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.71 72.29.91.71 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.72 72.29.91.72 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.73 72.29.91.73 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.74 72.29.91.74 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.75 72.29.91.75 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.76 72.29.91.76 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.77 72.29.91.77 netmask 255.255.255.255 0 0 static (priv,outside) 72.29.91.78 72.29.91.78 netmask 255.255.255.255 0 0 static (priv,net3) 72.29.91.66 72.29.91.66 netmask 255.255.255.255 0 0 static (net3,priv) 72.29.91.99 72.29.91.99 netmask 255.255.255.255 0 0 static (net3,priv) 72.29.91.98 72.29.91.98 netmask 255.255.255.255 0 0 static (net3,priv) 72.29.91.107 72.29.91.107 netmask 255.255.255.255 0 0 static (priv,reggie) 72.29.91.66 72.29.91.66 netmask 255.255.255.255 0 0 static (reggie,priv) 72.29.91.82 72.29.91.82 netmask 255.255.255.255 0 0 static (reggie,priv) 72.29.91.83 72.29.91.83 netmask 255.255.255.255 0 0 static (reggie,priv) 72.29.91.84 72.29.91.84 netmask 255.255.255.255 0 0 static (reggie,priv) 72.29.91.85 72.29.91.85 netmask 255.255.255.255 0 0 static (reggie,priv) 72.29.91.86 72.29.91.86 netmask 255.255.255.255 0 0 static (reggie,net3) 72.29.91.83 72.29.91.83 netmask 255.255.255.255 0 0 static (net4,outside) 72.29.91.114 72.29.91.114 netmask 255.255.255.255 0 0 static (net4,outside) 72.29.91.115 72.29.91.115 netmask 255.255.255.255 0 0 static (net4,outside) 72.29.91.116 72.29.91.116 netmask 255.255.255.255 0 0 static (net4,outside) 72.29.91.117 72.29.91.117 netmask 255.255.255.255 0 0 static (net4,outside) 72.29.91.118 72.29.91.118 netmask 255.255.255.255 0 0 static (net4,priv) 72.29.91.114 72.29.91.114 netmask 255.255.255.255 0 0 static (net4,reggie) 72.29.91.114 72.29.91.114 netmask 255.255.255.255 0 0 static (net4,net3) 72.29.91.114 72.29.91.114 netmask 255.255.255.255 0 0 static (net3,reggie) 72.29.91.99 72.29.91.99 netmask 255.255.255.255 0 0 static (net3,net4) 72.29.91.99 72.29.91.99 netmask 255.255.255.255 0 0 static (net3,reggie) 72.29.91.98 72.29.91.98 netmask 255.255.255.255 0 0 static (net3,net4) 72.29.91.98 72.29.91.98 netmask 255.255.255.255 0 0 conduit permit icmp any any conduit permit tcp host 72.29.91.84 eq www any conduit permit tcp host 72.29.91.84 eq https any conduit permit tcp host 72.29.91.84 eq 3389 any conduit permit tcp host 72.29.91.84 eq ftp any conduit permit tcp host 72.29.91.82 eq domain any conduit permit udp host 72.29.91.82 eq domain any conduit permit tcp host 72.29.91.82 eq ftp any conduit permit tcp host 72.29.91.82 eq www any conduit permit tcp host 72.29.91.82 eq https any conduit permit tcp host 72.29.91.82 eq 3389 any conduit permit tcp host 72.29.91.83 eq domain any conduit permit udp host 72.29.91.83 eq domain any conduit permit tcp host 72.29.91.83 eq pop3 any conduit permit tcp host 72.29.91.83 eq 3389 any conduit permit tcp host 72.29.91.83 eq ftp any conduit permit tcp host 72.29.91.83 eq smtp any conduit permit tcp host 72.29.91.85 eq www any conduit permit tcp host 72.29.91.85 eq ftp any conduit permit tcp host 72.29.91.85 eq https any conduit permit tcp host 72.29.91.85 eq 3389 any conduit permit tcp host 72.29.91.85 eq 7099 any conduit permit tcp host 72.29.91.83 eq www any conduit permit tcp host 72.29.91.83 eq imap4 any conduit permit tcp host 72.29.91.86 eq www any conduit permit tcp host 72.29.91.86 eq https any conduit permit tcp host 72.29.91.87 eq https any conduit permit tcp host 72.29.91.87 eq www any conduit permit tcp host 72.29.91.88 eq www any conduit permit tcp host 72.29.91.88 eq https any conduit permit tcp host 72.29.91.89 eq https any conduit permit tcp host 72.29.91.89 eq www any conduit permit tcp host 72.29.91.66 eq https any conduit permit tcp host 72.29.91.66 eq www any conduit permit tcp host 72.29.91.66 eq pop3 any conduit permit tcp host 72.29.91.66 eq imap4 any conduit permit tcp host 72.29.91.66 eq 3389 any conduit permit tcp host 72.29.91.66 eq smtp any conduit permit tcp host 72.29.91.66 eq 81 any conduit permit tcp host 72.29.91.67 eq www any conduit permit tcp host 72.29.91.67 eq https any conduit permit tcp host 72.29.91.68 eq https any conduit permit tcp host 72.29.91.68 eq www any conduit permit tcp host 72.29.91.69 eq www any conduit permit tcp host 72.29.91.69 eq https any conduit permit tcp host 72.29.91.69 eq 3389 any conduit permit tcp host 72.29.91.69 eq ftp any conduit permit tcp host 72.29.91.66 eq ftp any conduit permit tcp host 72.29.91.70 eq ftp any conduit permit tcp host 72.29.91.70 eq www any conduit permit tcp host 72.29.91.70 eq https any conduit permit tcp host 72.29.91.71 eq www any conduit permit tcp host 72.29.91.73 eq www any conduit permit tcp host 72.29.91.73 eq domain any conduit permit udp host 72.29.91.73 eq domain any conduit permit tcp host 72.29.91.73 eq https any conduit permit tcp host 72.29.91.76 eq domain any conduit permit udp host 72.29.91.76 eq domain any conduit permit tcp host 72.29.91.76 eq smtp any conduit permit tcp host 72.29.91.77 eq www any conduit permit tcp host 72.29.91.77 eq https any conduit permit tcp host 72.29.91.78 eq www any conduit permit tcp host 72.29.91.78 eq https any conduit permit tcp host 72.29.91.98 eq domain any conduit permit udp host 72.29.91.98 eq domain any conduit permit tcp host 72.29.91.98 eq www any conduit permit tcp host 72.29.91.99 eq domain any conduit permit udp host 72.29.91.99 eq domain any conduit permit tcp host 72.29.91.99 eq www any conduit permit tcp host 72.29.91.99 eq smtp any conduit permit tcp host 72.29.91.99 eq imap4 any conduit permit tcp host 72.29.91.99 eq pop3 any conduit permit tcp host 72.29.91.107 eq www any conduit permit tcp host 72.29.91.107 eq ftp any conduit permit tcp host 72.29.91.107 eq 3389 any conduit permit tcp host 72.29.91.108 eq 3389 any conduit permit tcp host 72.29.91.108 eq ftp any conduit permit tcp host 72.29.91.108 eq www any conduit permit tcp host 72.29.91.109 eq www any conduit permit tcp host 72.29.91.109 eq ftp any conduit permit tcp host 72.29.91.109 eq 3389 any conduit permit tcp host 72.29.91.74 eq www any conduit permit tcp host 72.29.91.114 eq ssh any conduit permit tcp host 72.29.91.114 eq smtp any conduit permit tcp host 72.29.91.114 eq pop3 any conduit permit tcp host 72.29.91.114 eq imap4 any conduit permit tcp host 72.29.91.114 eq domain any conduit permit udp host 72.29.91.114 eq domain any conduit permit tcp host 72.29.91.114 eq www any conduit permit tcp host 72.29.91.114 eq https any conduit permit tcp host 72.29.91.114 eq ftp-data any conduit permit tcp host 72.29.91.114 eq ftp any conduit permit tcp host 72.29.91.114 eq 993 any conduit permit tcp host 72.29.91.114 eq 995 any conduit permit tcp host 72.29.91.115 eq ssh any conduit permit tcp host 72.29.91.115 eq smtp any conduit permit tcp host 72.29.91.115 eq pop3 any conduit permit tcp host 72.29.91.115 eq imap4 any conduit permit tcp host 72.29.91.115 eq domain any conduit permit udp host 72.29.91.115 eq domain any conduit permit tcp host 72.29.91.115 eq www any conduit permit tcp host 72.29.91.115 eq https any conduit permit tcp host 72.29.91.115 eq ftp-data any conduit permit tcp host 72.29.91.115 eq ftp any conduit permit tcp host 72.29.91.115 eq 993 any conduit permit tcp host 72.29.91.115 eq 995 any conduit permit tcp host 72.29.91.103 eq www any conduit permit tcp host 72.29.91.104 eq www any conduit permit tcp host 72.29.91.105 eq www any conduit deny ip any any outbound 1 permit 0.0.0.0 0.0.0.0 0 ip apply (inside) 1 outgoing_src apply (reggie) 1 outgoing_src apply (net3) 1 outgoing_src apply (net4) 1 outgoing_src route outside 0.0.0.0 0.0.0.0 72.29.91.126 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout sip-disconnect 0:02:00 sip-invite 0:03:00 timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+ aaa-server TACACS+ max-failed-attempts 3 aaa-server TACACS+ deadtime 10 aaa-server RADIUS protocol radius aaa-server RADIUS max-failed-attempts 3 aaa-server RADIUS deadtime 10 aaa-server LOCAL protocol local no snmp-server location no snmp-server contact snmp-server community public no snmp-server enable traps floodguard enable telnet timeout 5 ssh timeout 5 console timeout 0 terminal width 80 Cryptochecksum:3d0e96df8a545fcb3aa924794e17f3a1