Michael J McCafferty wrote:
The ports that have blown have been on two different cards in the chassis. In
each case the port that blew was plugged in to the same Cisco Ethernet switch. The first time this happened, it took some time to diagnose becuase we were
able to see traffic at the interface that was "blown" (using a tcpdump-like
command on the FW), but the switch did not have a MAC address for the firewall
port. The firewall did have a MAC address for the switch though.

To what model catalyst is the firewall appliance connected? 6500s, 4500s, 3550s, 3560s, 3750s, and 3760s (and several other switch models) can be ordered with Power over Ethernet modules. Some devices do not gracefully handle PoE, and you end up with barbequed hardware. Fortunately, catalysts have the option to shut PoE off on ports you don't need it on. In fact, it is typically this way by default (as to not damage equipment). But, it's worth looking into.

We switched out the cable, changed the port on the switch, shutdown and brought
back up the interface on the FW, etc. The only thing that finally fixed the
problem was moving the security zone to a new interface on the firewall, and
moving the cable to that new interface. This has happened 3x in 3 weeks.

What kind of firewall appliace is this? A Sonicwall? A NetScreen?

So, the question is: What's up with that zone/switch that is blowing interfces
on our firewall ? I am getting tired of getting called in the wee hours
(begining of the business day in Europe) for blown ports on this important
firewall. Naturally, this interface is the most critical zone on the FW.

Software shouldn't have the ability to make hardware die a miserable death. If the software in the unit does, I'd consider a) upgrading it b) moving to another product that sets sane limitations

The FW and switch is in a computer room with UPS protection. Can it be a ground
problem ? Can the switch be having electrical issues that are damaging my FW ?
Naturally, since this is a huge company, the switch is managed by another
company who is glad to assume the problem is our FW and not their switch.

Most commercial equipment is chassis grounded. As per electric code (at least in the US) equipment racks must also be grounded. So, if your machine is screwed into the rack, it should have a solid ground. Check for transients on the power line (unlikely, as other equipment would end up barbequed). Have someone put a 125+dB filter (or one of those $100 power strips) between the firewall appliance and the mains source. No, actually, just replace the PDU in the rack servicing the firewall.

It could also be the PSU in the firewall itself. I've seen failing PSUs do great things like lock open (Vinput = Voutput -- can we say, "goodbye" to the magic smoke?). Since most PSUs implement switching power supplies, which work by quickly switching the input power on and off in order to get the voltage required at the output, when they fail, they can fail catastrophically.

either way, i'd invoke your support agreement with the manufacturer of the firewall (you *do* have a support agreement, right?) and make them replace it. It certainly wouldn't hurt too much.

good luck,
-kelsey


--
[email protected]
http://www.kernel-panic.org/cgi-bin/mailman/listinfo/kplug-list

Reply via email to