![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Security and Firewalls Protecting you against unwanted people and programs |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 3
OS: winxpsp2
|
pix515e vpn site-to-site resetting tunnel
hi all,
i have setup vpn site-to-site between head and branch office. the tunnel created is good. user on branch can access apps server on head office. but sometimes they complain, when they access oracle apps they keep getting message 'server interruption' and they have to re-login. my question is does this problem because there is somekind of buffer inside pix full? both side using same pix: Cisco PIX Firewall Version 6.3(1) Licensed Features: Failover: Enabled VPN-DES: Enabled VPN-3DES-AES: Enabled Maximum Interfaces: 6 Cut-through Proxy: Enabled Guards: Enabled URL-filtering: Enabled Inside Hosts: Unlimited Throughput: Unlimited IKE peers: Unlimited UR License here is result of debug cry isakmp: ISADB: reaper checking SA 0xff7cfc, conn_id = 0 rgds, -dewo- |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Moderator Networking Team
Join Date: Aug 2006
Location: Canada
Posts: 2,664
OS: Windows Vista Business SP1, Windows XP Professional SP3
|
Re: pix515e vpn site-to-site resetting tunnel
Have there been any drops or losses over the tunnel while using other apps other than Oracle?
There "shouldn't" be any problems like that, in the case of overloading PIX (especially if you have failover), unless you are using the appliance beyond its design limits. It's possible that Oracle isn't being very lenient in terms of timeout, in which case you may wish to reconfigure it with longer timeouts. |
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 3
OS: winxpsp2
|
Re: pix515e vpn site-to-site resetting tunnel
Usually when oracle apps being dropped, other application like outlook, terminal service are either getting slower or dropped also.
I have googling anywhere to find relevant issue but see none. What i'm doing now is clear xlate table or power cycle the pix box. we have submit this problem to oracle metalink. -dewo- |
|
|
|
|
|
#4 (permalink) |
|
Moderator Networking Team
Join Date: Aug 2006
Location: Canada
Posts: 2,664
OS: Windows Vista Business SP1, Windows XP Professional SP3
|
Re: pix515e vpn site-to-site resetting tunnel
It is possible that you are over-extending your WAN link. When the slowdowns/drop-outs occur, take a look at the WAN link's throughput and see if you are approaching or near its upper limit.
What do you use for your WAN link. Do you have a guaranteed rate for it? |
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 3
OS: winxpsp2
|
Actually i'm using ip vpn and i am not on WAN link. the vpn tunnel create over internet. i saw when the connection is dropped/slowed, my internet b/w seems to be exhausted. but that's not it, even in the morning when not many users were accessing the internet, oracle/mail get dropped for remote users.
FYI, i'm in indonesia (HQ) and my remote site is in Singapore. We are using similar device and topology, the difference is we have vlans (HQ) and i think it doesnt matter. both sites have own internet access. i simply implement what cisco called site-to-site vpn config
|
|
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Oct 2008
Posts: 1
OS: Windows XP
|
Re: pix515e vpn site-to-site resetting tunnel
Dewo,
Because you are using an IP tunnel over the Internet technically you have extended your LAN to include a remote site which qualifies as a WAN connection. In any case Cellus is on the right track I think because that is what happened to us a couple of years back with our PIX 515e device. We were seeing Citrix sessions dropping or users complaining it was real slow, SSH connections would connect but not present the login prompt through the NAT, etc... we checked the Internet line and lo and behold it was pegged at it's 15 mb/s cap so we upped it and as soon as we did that everythign returned to normal operation. PDM was the tool that showed this to us. Simply installed it into the PIX and the graph showed us without any hesitation where the issue lay. Mike. |
|
|
|
![]() |
| Thread Tools | |
|
|