PIX NAT/PAT IP locks up, but static conduits continue - How to track bad pc?

Sep 11, 2007 1 Replies

We use a PIX 515 and we have about 275 users going out a 3 mbps pipe. It has worked well for years. This morning for 2 hours, the pcs that all share an external ip address via dynamic NAT/PAT failed to hit the Internet. The PCs/servers that have a static route through the firewall via conduits worked fine. If I did a clear xlate, the problem went away. It stayed gone for about an hour and then all those sharing the ip froze again. I did a clear xlate and it cleared up and stayed OK. If I did a show xlate before clearing, the listing went on practically forever. I have all the switches go to a hub and then the cisco so I can hook up a laptop to the hub that has ntop on it. That in the past has helped me find if a particular pc is hogging all the bandwidth. This time however, there was actually very little Mb moved across the period and it all made sense - mail server web access server etc. Is there a program I can use free or through purchase that will tell me what ip is causing all these translations to come about? I think that must be the answer. When someone is streaming video or downloading a huge file, all traffic is slow. If you had a static IP today, you didn't even know there was a problem...the speed was fine. The fact that it instantly solves after clear xlate has led me to this. Any words of wisdom? Thanks for your help.



Capture the translations to a file, sort 'em by the inside PC address and see which one has an inordinate number of mappings.

Perhaps one of upur users has been hijacked by a broken spambot that doesn't properly clean up after itself.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required