Cisco pix – external interface goes down – is this the pix or network

ciscocisco-pixnetworking

In December our Cisco PIX 501 appeared to hang taking the webservers behind it offline. It did this 4 times in the space of a couple of weeks and the "remote hands" engineer at the data-centre (where everything is colocated) reported:

simply rebooting the box once didn't work. We had to reboot the box several times and even re-seat the port0 cable before it would come back online.

So we replaced the PIX with a spare (501), same config installed and everything looked ok. Except this PIX "hung" yesterday. The problem is with the external interface because we can connect to the PIX from an internal IP and show int returns

interface ethernet0 "outside" is up, line protocol is down
Hardware is i82559 ethernet, address is 0000.1234....
IP address x.x.x.x, subnet mask 255.255.255.0

The router that our PIX's external interface is connecting to also reports the line down:

%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/32, changed state to down
%LINK-3-UPDOWN: Interface FastEthernet0/32, changed state to down
%LINK-3-UPDOWN: Interface FastEthernet0/32, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/32, changed state to up

How do I work out what is causing the line to drop? We have replaced the physical firewall, the network cable and the ports that the cable connects to. We've got informational logging running (using Kiwi) and can also see the line going down there but no idea why:

411002: Line protocol on Interface outside, changed state to down

Last time it happened, we tried shutting down and restarting the external interface – no joy, reload the PIX, no joy, changing the interface to 100full (for some reason it shows up as half-duplex when it was on auto), no joy. The line came back up "on its own" after a few minutes, not in response to anything we were trying (I think). I'm not convinced it's the PIX, data-centre thinks it's us…

Best Answer

Ask them to switch you to a different network port: you've got the half-duplex thing, and it taking a few minutes to bring the line up. Also, how well was your spare pix tested, are you sure it isn't another dud?

Related Topic