Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Replacing a PIX 515E with a PIX 515

Reply
Thread Tools

Replacing a PIX 515E with a PIX 515

 
 
Dustin
Guest
Posts: n/a
 
      11-05-2005
I have a PIX 515E that I am currently using as our main firewall,
attached to a T1. I am getting a 4mb connection (over 10mb ethernet)
at a colo facility, and I would like to move this PIX 515E over there.
In order to do this, I need to take a PIX 515 that I have and get it to
work identically. I have copy/pasted the config from the 515E to the
515, I have copy the 515E's config to a tftp server, and then download
it to the 515 by tftp. The PIX 515 is somewhat functional.

Each unit has 64MB RAM, 16MB Flash, UR License, VAC card, and 4 FE
card. The 515E has PIX OS 6.3(4), and the 515 has PIX OS 6.3(5). I
have used a diff to see if there are any major changes after loading,
and I see none. The PIX 515 works for access from Inside to DMZ and
Outside, and from the DMZ to Outside... but none of the ACLs work for
traffic from Outside to DMZ or Inside, or DMZ to Inside.

Any ideas?


Thanks,
Dustin

 
Reply With Quote
 
 
 
 
Matty M
Guest
Posts: n/a
 
      11-05-2005

"Dustin" <> wrote in message
news: oups.com...
>I have a PIX 515E that I am currently using as our main firewall,
> attached to a T1. I am getting a 4mb connection (over 10mb ethernet)
> at a colo facility, and I would like to move this PIX 515E over there.
> In order to do this, I need to take a PIX 515 that I have and get it to
> work identically. I have copy/pasted the config from the 515E to the
> 515, I have copy the 515E's config to a tftp server, and then download
> it to the 515 by tftp. The PIX 515 is somewhat functional.
>
> Each unit has 64MB RAM, 16MB Flash, UR License, VAC card, and 4 FE
> card. The 515E has PIX OS 6.3(4), and the 515 has PIX OS 6.3(5). I
> have used a diff to see if there are any major changes after loading,
> and I see none. The PIX 515 works for access from Inside to DMZ and
> Outside, and from the DMZ to Outside... but none of the ACLs work for
> traffic from Outside to DMZ or Inside, or DMZ to Inside.
>
> Any ideas?
>
>
> Thanks,
> Dustin
>


Hi,

Should be identical. The only difference would be the 515E has a faster CPU
and can take more RAM from memory. Are all the interfaces called the same on
both PIX's? It maybe that your access lists arent bound to the right names
of the interface cards.

Cheers

Matt


 
Reply With Quote
 
 
 
 
Dustin
Guest
Posts: n/a
 
      11-08-2005
I spoke with someone from TAC. She recommended that we reset the ARP
cache on our router. I did not think that this was a possible reason,
at first, because the PIX was forwarding outbound traffic properly.
Because of this, I was pretty sure that the ARP information has been
reset.

After looking at the ARP cache on our router, I saw that the default
cache is 4 hours, and that each IP that was being translated had a
separate entry (which does make sense). It is odd how you never really
think about certain basic things, because they rarely present problems.

I am going to make another go of it tomorrow morning, and I am going to
look at the ARP cache and reset if necesary.

 
Reply With Quote
 
Matty M
Guest
Posts: n/a
 
      11-08-2005

"Dustin" <> wrote in message
news: oups.com...
>I spoke with someone from TAC. She recommended that we reset the ARP
> cache on our router. I did not think that this was a possible reason,
> at first, because the PIX was forwarding outbound traffic properly.
> Because of this, I was pretty sure that the ARP information has been
> reset.
>
> After looking at the ARP cache on our router, I saw that the default
> cache is 4 hours, and that each IP that was being translated had a
> separate entry (which does make sense). It is odd how you never really
> think about certain basic things, because they rarely present problems.
>
> I am going to make another go of it tomorrow morning, and I am going to
> look at the ARP cache and reset if necesary.
>


I was under the impression that the ARP cleared itself after a while or even
when you switch the PIX on/reboot it. I know that clear xlate is a good one
when your changing access lists but I thought they were not working at all
when you turned the PIX on?

Cheers

Matt


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Moving Config from PIX 515 to 515e Scott Townsend Cisco 3 05-13-2008 01:56 PM
PIX 515 and 515E franklin.28@gmail.com Cisco 2 08-25-2006 03:49 PM
PIX 515 to PIX 515e not passing traffic Scott Townsend Cisco 6 05-25-2006 11:03 AM
PIX 515 to PIX 515 via Internet & IPSec, should I get a VAC? Scott Townsend Cisco 8 02-22-2006 09:59 PM
Upgrade PIX 515 to 515E or get 506 for Branch Office? Scott Townsend Cisco 2 02-21-2006 11:59 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57