Q: Could the wrong cable cause this behavior?

G

Guest

Guest
Archived from groups: comp.security.firewalls (More info?)

My Netscreen 5GT instructions said to use the cross-over cable between my
firewall and my switch. I accidentally used the straight through cable. I
realized this as I was packing it up to return it for a new one thinking the
unit itself was bad. Could this cause the behaviour I've been seeing?

1. The unit runs great for 4-8 hours with no CRC errors, no collisions,
although it does pick up a bunch of "out defer" errors every hour.

2. Then, I lose access through firewall to my websites (HTTP, FTP, Mail).
Sometimes, it happens only to certain networks on the untrust side, like
MSN, or Sprint, but not to users coming over Qwest, or sometimes all!

3. I NEVER lose access to my servers through a custom protocol for RDP I
setup in the same firewall. Note, that the IIS webserver has about 10
public IP's bound it and the RDP goes to one IP, while all the web traffic
described in #2 goes to another.

4. I can restore traffic through the firewall by unplugging the Untrust
ethernet for a few seconds and then plugging it back in.

Any ideas what is going on here?
thanks,
Blaker
 

Mike

Splendid
Apr 1, 2004
3,865
0
22,780
Archived from groups: comp.security.firewalls (More info?)

"blaker" <anonymous@nowhere.com> wrote in message
news:Vgxnc.13624$V97.9584@newsread1.news.pas.earthlink.net...
> My Netscreen 5GT instructions said to use the cross-over cable between my
> firewall and my switch. I accidentally used the straight through cable.
I
> realized this as I was packing it up to return it for a new one thinking
the
> unit itself was bad. Could this cause the behaviour I've been seeing?

NO. I suspect you have an autosensing switch. Please supply make & model so
we may confirm this
 
G

Guest

Guest
Archived from groups: comp.security.firewalls (More info?)

My Netscreen 5GT Firewall has both Trust and Untrust sides set to 10/FDX,
and I verified that the internet feed is also 10/FDX.

My switch is a HP ProCurve 2512. I have it set to:

1 10FDX on the untrust side (port 1)
2. 100FDX on the untrust side (port 2, 3), Flow Control = Enable
3. 100FDX on each of the servers NIC cards, Flow Control = Generate and
Repsond

So, I've confirmed that there are not "auto" ports anywhere in my systems,
and I did try the crossover cable to no avail, still got another lockout of
HTTP after about 4 hours of operation this time.

thanks,
Blaker


"Mike" <nospam@notherematey.com> wrote in message
news:c7nf7i$g6c$1@thorium.cix.co.uk...
>
> "blaker" <anonymous@nowhere.com> wrote in message
> news:Vgxnc.13624$V97.9584@newsread1.news.pas.earthlink.net...
> > My Netscreen 5GT instructions said to use the cross-over cable between
my
> > firewall and my switch. I accidentally used the straight through cable.
> I
> > realized this as I was packing it up to return it for a new one thinking
> the
> > unit itself was bad. Could this cause the behaviour I've been seeing?
>
> NO. I suspect you have an autosensing switch. Please supply make & model
so
> we may confirm this
>
>