Here's one that I am having difficulty with. Your thoughts would be appreciated.

I have a large chassis-based firewall appliance at a customer site in Europe.
There are 8 different zones on this fiewall. On one of the zones, the Ethernet
port has blown 3 times so far in the 3 weeks the firewall has been installed.
This firewall replaced another firewall of a differrent brand, which was old
and managed by another company than ours.

The ports that have blown have been on two different cards in the chassis. In
each case the port that blew was plugged in to the same Cisco Ethernet switch. 
The first time this happened, it took some time to diagnose becuase we were
able to see traffic at the interface that was "blown" (using a tcpdump-like
command on the FW), but the switch did not have a MAC address for the firewall
port. The firewall did have a MAC address for the switch though.

We switched out the cable, changed the port on the switch, shutdown and brought
back up the interface on the FW, etc. The only thing that finally fixed the
problem was moving the security zone to a new interface on the firewall, and
moving the cable to that new interface. This has happened 3x in 3 weeks.

So, the question is: What's up with that zone/switch that is blowing interfces
on our firewall ? I am getting tired of getting called in the wee hours
(begining of the business day in Europe) for blown ports on this important
firewall. Naturally, this interface is the most critical zone on the FW.

The FW and switch is in a computer room with UPS protection. Can it be a ground
problem ? Can the switch be having electrical issues that are damaging my FW ?
Naturally, since this is a huge company, the switch is managed by another
company who is glad to assume the problem is our FW and not their switch.

Thoughts ?

Thanks,
Mike

-- 
************************************************************
Michael J. McCafferty
Principal, Security Engineer
M5 Hosting
858-576-7325 Voice
http://www.m5hosting.com
************************************************************


-- 
[email protected]
http://www.kernel-panic.org/cgi-bin/mailman/listinfo/kplug-list

Reply via email to