Desperate for Netscreen help

Mar 26, 2005 1 Replies

Small shop (25 users) running a Netscreen 5XP (10/unlimited). Have an Exchange server which when trying to ping the inside interface of the firewall, fails 9 out of 10 times, can't browse the web and email gets delayed being sent. All other servers/workstations are fine. When I go on the firewall, I do a "get session" and it shows about 171 Alloc\\2048 Max. (so it looks like pleny available) but when I do a "clear session", the Exchange server can ping no problem for about 3 minutes...then gets hung up again. Receiving mail is always fine. On the 5XP alert page, I'm seeing entries such as this...(10.0.254.2 is the Exchange server)...


2005-03-26 05:59:50 crit session threshold, From 10.0.254.2/1133 to
4.2.2.1/53, using protocol UDP (on zone Trust,interface trust) occurred 13 times
2005-03-26 05:59:48 crit session threshold, From 10.0.254.2/34903 to
66.111.229.116/25, using protocol TCP (on zone Trust,interface trust) occurred 12 times
2005-03-26 05:59:48 crit session threshold, From 10.0.254.2/1133 to
4.2.2.1/53, using protocol UDP (on zone Trust,interface trust) occurred 11 times
2005-03-26 05:59:46 crit session threshold, From 10.0.254.2/34893 to
195.110.124.83/25, using protocol TCP (on zone Trust,interface trust) occurred 16 times
2005-03-26 05:59:44 crit session threshold, From 10.0.254.2/34886 to
66.111.229.118/25, using protocol TCP (on zone Trust,interface trust)
2005-03-26 05:59:44 crit session threshold, From 10.0.254.2/1133 to
4.2.2.1/53, using protocol UDP (on zone Trust,interface trust) occurred 8 times

Any suggestions on how to fix this issue?? Does the netscreen limit a particular IP to a certain number of sessions?


Not deperate anymore...found the set firewall session-threshold source-ip-based [num] command which fixed the issue.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required