CSCue51351 - ASA NAT huge config causes traceback because of the unbalanced tree p3

Hi experts ASA

CSCue51351 - ASA NAT huge config causes traceback because of the unbalanced tree p3

I want to know that how huge?

Below, this Condition of DDT is SSP60.

----------------------

Symptom:

Version 9 8.4 (4) current ASA code can generate a traceback with thread name: DATAPATH-7-2315 and reload.

Conditions:

Seen on ASA5585-SSP-60 running in the failover environment.

Workaround solution:

None

----------------------

SSP60 can perform up to 10 000 000 simultaneous sessions.

It's more than 10 000 000 simultaneous sessions?

Kind regards.

Word

Hello Word,

This flaw does not affect the number of concurrent sessions.

Instead, this fault comes to play if you have a large number of statements NAT or ACL (say 25 k +) which you change and at the same time the unit treats a large number of new connections per second (say 20 k +), what then is there the possibility of hitting this issue.

Sincerely,

David.

Tags: Cisco Tools

Similar Questions

  • ASA Anyconnect VPN do not work or download the VPN client

    I have a Cisco ASA 5505 that I try to configure anyconnect VPN and thought, I've changed my setup several times but trying to access my static public IP address of the external IP address to download the image, I am not able to. Also when I do a package tracer I see he has been ignored through the acl when the packets from side to the ASA via port 443, it drops because of the ACL. My DMZ so will he look like something trying to access the ASA via the VPN's going to port 443. Here is my config

    XXXX # sh run
    : Saved
    :
    ASA Version 8.4 (3)
    !
    hostname XXXX
    search for domain name
    activate pFTzVNrKdD9x5rhT encrypted password
    zPBAmb8krxlXh.CH encrypted passwd
    names of
    !
    interface Ethernet0/0
    Outside-interface description
    switchport access vlan 20
    !
    interface Ethernet0/1
    Uplink DMZ description
    switchport access vlan 30
    !
    interface Ethernet0/2
    switchport access vlan 10
    !
    interface Ethernet0/3
    switchport access vlan 10
    !
    interface Ethernet0/4
    Ganymede + ID description
    switchport access vlan 10
    switchport monitor Ethernet0/0
    !
    interface Ethernet0/5
    switchport access vlan 10
    !
    interface Ethernet0/6
    switchport access vlan 10
    !
    interface Ethernet0/7
    Description Wireless_AP_Loft
    switchport access vlan 10
    !
    interface Vlan10
    nameif inside
    security-level 100
    IP 192.168.10.1 255.255.255.0
    !
    interface Vlan20
    nameif outside
    security-level 0
    IP address x.x.x.249 255.255.255.248
    !
    Vlan30 interface
    no interface before Vlan10
    nameif dmz
    security-level 50
    IP 172.16.30.1 255.255.255.0
    !
    boot system Disk0: / asa843 - k8.bin
    passive FTP mode
    DNS lookup field inside
    DNS domain-lookup outside
    DNS domain-lookup dmz
    DNS server-group DefaultDNS
    Name-Server 8.8.8.8
    Server name 8.8.4.4
    search for domain name
    network obj_any1 object
    subnet 0.0.0.0 0.0.0.0
    network of the Webserver_DMZ object
    Home 172.16.30.8
    network of the Mailserver_DMZ object
    Home 172.16.30.7
    the object DMZ network
    172.16.30.0 subnet 255.255.255.0
    network of the FTPserver_DMZ object
    Home 172.16.30.9
    network of the Public-IP-subnet object
    subnet x.x.x.248 255.255.255.248
    network of the FTPserver object
    Home 172.16.30.8
    network of the object inside
    192.168.10.0 subnet 255.255.255.0
    network of the VPN_SSL object
    10.101.4.0 subnet 255.255.255.0
    outside_in list extended access permit tcp any newspaper object Mailserver_DMZ eq www
    outside_in list extended access permit tcp any newspaper EQ 587 Mailserver_DMZ object
    outside_in list extended access permit tcp any newspaper SMTP object Mailserver_DMZ eq
    outside_in list extended access permit tcp any newspaper of the Mailserver_DMZ eq pop3 object
    outside_in list extended access permit tcp any newspaper EQ 2525 Mailserver_DMZ object
    outside_in list extended access permit tcp any newspaper of the Mailserver_DMZ eq imap4 object
    outside_in list extended access permit tcp any newspaper EQ 465 Mailserver_DMZ object
    outside_in list extended access permit tcp any newspaper EQ 993 Mailserver_DMZ object
    outside_in list extended access permit tcp any newspaper EQ 995 object Mailserver_DMZ
    outside_in list extended access permit tcp any newspaper EQ 5901 Mailserver_DMZ object
    outside_in list extended access permit tcp any newspaper Mailserver_DMZ eq https object
    Note access list ACL for VPN Tunnel from Split vpn_SplitTunnel
    vpn_SplitTunnel list standard access allowed 192.168.10.0 255.255.255.0
    pager lines 24
    Enable logging
    timestamp of the record
    exploitation forest-size of the buffer to 8192
    logging trap warnings
    asdm of logging of information
    Within 1500 MTU
    Outside 1500 MTU
    MTU 1500 dmz
    local pool VPN_SSL 10.101.4.1 - 10.101.4.4 255.255.255.0 IP mask
    ICMP unreachable rate-limit 1 burst-size 1
    ASDM image disk0: / asdm - 647.bin
    don't allow no asdm history
    ARP timeout 14400
    NAT (inside, outside) static source inside inside static destination VPN_SSL VPN_SSL
    NAT (exterior, Interior) static source VPN_SSL VPN_SSL
    !
    network obj_any1 object
    NAT static interface (indoor, outdoor)
    network of the Webserver_DMZ object
    NAT (dmz, outside) static x.x.x.250
    network of the Mailserver_DMZ object
    NAT (dmz, outside) static x.x.x.. 251
    the object DMZ network
    NAT (dmz, outside) static interface
    Access-group outside_in in external interface
    Route outside 0.0.0.0 0.0.0.0 x.x.x.254 1
    Timeout xlate 03:00
    Pat-xlate timeout 0:00:30
    Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00
    Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00
    Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    Floating conn timeout 0:00:00
    dynamic-access-policy-registration DfltAccessPolicy
    AAA-server protocol Ganymede HNIC +.
    AAA-server host 192.168.10.2 HNIC (inside)
    Timeout 60
    key *.
    identity of the user by default-domain LOCAL
    Console HTTP authentication AAA HNIC
    AAA console HNIC ssh authentication
    Console AAA authentication telnet HNIC
    AAA authentication secure-http-client
    http 192.168.10.0 255.255.255.0 inside
    No snmp server location
    No snmp Server contact
    Server enable SNMP traps snmp authentication linkup, linkdown cold start
    Crypto ca trustpoint localtrust
    registration auto
    Configure CRL
    Crypto ca trustpoint VPN_Articulate2day
    registration auto
    name of the object CN = vpn.articulate2day.com
    sslvpnkey key pair
    Configure CRL
    Telnet 192.168.10.0 255.255.255.0 inside
    Telnet timeout 30
    SSH 192.168.10.0 255.255.255.0 inside
    SSH timeout 15
    SSH version 2
    Console timeout 0
    No vpn-addr-assign aaa

    DHCP-client update dns
    dhcpd dns 8.8.8.8 8.8.4.4
    dhcpd outside auto_config
    !
    dhcpd address 192.168.10.100 - 192.168.10.150 inside
    dhcpd allow inside
    !
    dhcpd address dmz 172.16.30.20 - 172.16.30.23
    dhcpd enable dmz
    !
    a basic threat threat detection
    Statistics-list of access threat detection
    no statistical threat detection tcp-interception
    authenticate the NTP
    NTP server 192.168.10.2
    WebVPN
    allow outside
    AnyConnect image disk0:/anyconnect-linux-64-3.1.06079-k9.pkg 1
    AnyConnect enable
    tunnel-group-list activate
    internal VPN_SSL group policy
    VPN_SSL group policy attributes
    value of server DNS 8.8.8.8
    client ssl-VPN-tunnel-Protocol
    Split-tunnel-policy tunnelspecified
    value of Split-tunnel-network-list vpn_SplitTunnel
    the address value VPN_SSL pools
    WebVPN
    activate AnyConnect ssl dtls
    AnyConnect Dungeon-Installer installed
    AnyConnect ssl keepalive 15
    AnyConnect ssl deflate compression
    AnyConnect ask enable
    ronmitch50 spn1SehCw8TvCzu7 encrypted password username
    username ronmitch50 attributes
    type of remote access service
    type tunnel-group VPN_SSL_Clients remote access
    attributes global-tunnel-group VPN_SSL_Clients
    address VPN_SSL pool
    Group Policy - by default-VPN_SSL
    tunnel-group VPN_SSL_Clients webvpn-attributes
    enable VPNSSL_GNS3 group-alias
    type tunnel-group VPN_SSL remote access
    !
    class-map inspection_default
    match default-inspection-traffic
    !
    !
    type of policy-card inspect dns preset_dns_map
    parameters
    maximum message length automatic of customer
    message-length maximum 512
    Policy-map global_policy
    class inspection_default
    inspect the preset_dns_map dns
    inspect the ftp
    inspect h323 h225
    inspect the h323 ras
    inspect the rsh
    inspect the rtsp
    inspect sqlnet
    inspect the skinny
    inspect sunrpc
    inspect xdmcp
    inspect the sip
    inspect the netbios
    inspect the tftp
    Review the ip options
    inspect esmtp
    !
    global service-policy global_policy
    context of prompt hostname
    no remote anonymous reporting call
    call-home
    Profile of CiscoTAC-1
    no active account
    http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address
    email address of destination [email protected] / * /
    destination-mode http transport
    Subscribe to alert-group diagnosis
    Subscribe to alert-group environment
    Subscribe to alert-group monthly periodic inventory
    monthly periodicals to subscribe to alert-group configuration
    daily periodic subscribe to alert-group telemetry
    Cryptochecksum:d41d8cd98f00b204e9800998ecf8427e
    : end

    XXXX #.

    You do not have this configuration:

     object network DMZ nat (dmz,outside) static interface

    Try and take (or delete):

     object network DMZ nat (dmz,outside) dynamic interface

  • ASA NAT 9.1 as object under standalone vs NAT command command

    Hey guys,.

    I'm setting up a few new 5515 X ASAs.

    Are there major differences between the two methods of syntax NAT?  They both seem to work in a lab environment.  I find that the first method mentioned in the Cisco documentation for one-to-one NAT static execution, however.

    Method 1:

    network of the object Test-DMZ-Server_EXT
    Home 172.25.1.2
    network of the LOCAL-RANGE_EXT object
    Home 172.17.1.2

    network of LOCAL-RANGE object
    host 192.168.10.2
    NAT (inside, outside) static LOCAL-RANGE_EXT
    network of the DMZ-Test Server object
    Home 192.168.199.2
    NAT (DMZ, all) public static Test-DMZ-Server_EXT
    network of the ANY object
    subnet 0.0.0.0 0.0.0.0
    dynamic NAT (all, outside) interface

    Method 2:

    network of LOCAL-RANGE object
    host 192.168.10.2
    network of the DMZ-Test Server object
    Home 192.168.199.2
    network of the object Test-DMZ-Server_EXT
    Home 172.25.1.2
    network of the LOCAL-RANGE_EXT object
    Home 172.17.1.2

    NAT (DMZ, all) source static-DMZ-Server Test Test-DMZ-Server_EXT
    NAT (insdie, outside) Shared source LOCAL-RANGE-LOCAL-RANGE_EXT

    NAT (all, outside) source Dynamics one interface

    Thank you

    Hello

    Both formats of configuration can achieve the same thing.

    The first is Auto NAT / NAT network of the object where the user configures the configuration complete "nat" under the created 'object'. Generally, this format of configuration is used to configure static dynamic static NAT PAT and PAT at least.

    The second configuration is twice the NAT / manual NAT who uses different configurations 'object' and ' object-group ' to list the addresses/actual in the NAT configurations. This "nat" configuration is not located under objects, but rather to use them. Generally, this format of configuration is used to configure the NAT type NAT0 configurations or policy.

    While the two configuration to achieve the same there is a big difference between them. In the new NAT configuration format introduced in paragraph 8.3, NAT configurations are divided into 3 Sections which sets their priority in the "nat" configurations

    They are as follows

    • Article 1 = manual NAT / twice by NAT
    • Section 2 = Auto NAT / NAT network object
    • Section 3 = manual NAT / twice by NAT
      • a parameter added "after the automatic termination" is required to move this Section 3 configuration

    So depending on what format you use you might find yourself of the substitution of some other configuration by inserting article 1 configuration (what you are doing by using the manual NAT / double configuration NAT format). Well I would say that it becomes a problem that in some situations in simple firewall configurations. I would say that the problem the most common here on the forums is usually when a user has configured a dynamic PAT in the Section 1 and static PAT (Port Forward) in Section 2, and uses the same public IP as PAT address both. This creates a situation where all traffic from external networks is the dynamic configuration PAT in Section 1, rather than any static configuration PAT in Section 2.

    Another big difference between NAT Auto and manual NAT is the fact that NAT Auto does that source address translation (which may seem odd depending on which side you are looking for the situation) while Manuel NAT can do the conversion for the source and destination IP address. But that you configure static NAT, it didn't really matter. The two formats NAT can achieve the same thing.

    Ultimately nothing for example prevents you all just about everything using Section 1 Manual NAT if you wanted to. You can set up no matter what type of NAT you wanted on this stretch alone and would not use NAT Auto at all if it was your wish. But I would say that's not suggestable and even less so if you have a large NAT configuration.

    My personal suggestion in brief is as follows

    • Article 1 = use of the configurations type NAT0 and static/dynamic policy NAT as these configurations are usually intended to replace typical NAT configurations.
    • Section 2 = use static and static NAT PAT that this provides the format of simpler configuration for the listed configurations and they are still quite high in priority being in Section 2. NAT configuration manual would require several configurations of 'object' to achieve the same.
    • Section 3 = Place all your Dynamic NAT/PAT or NAT + PAT configurations here because this should be the last connection NAT must match in all cases when it has nothing specifically designed for guests.

    I find that with the above way you keep your severed much NAT configuration and know what where. The configuration is also a little less cluttered when configurations are not in the same Section.

    If you want to read more about the new format of configuration NAT you can check out a document, I wrote here in 2013. Although it includes the things I mentioned above also.

    https://supportforums.Cisco.com/document/132066/ASA-NAT-83-NAT-operation...

    You can of course ask here in this discussion if you want :)

    Remember to mark a reply as the answer if it answered your question.

    Hope this helps :)

    -Jouni

  • I want to disable the USN journal because of the huge size and fragmentation

    In fact, I decided to use Windows again after 7 is out and seems relatively stable.  I've been a Linux user for many years.

    I want to disable the USN journal because of the huge size and fragmentation; I am not concerned about its performance in the fragmentation, I am concerned about the fragmentation of other files that it encourages rather SHORT time same amounts.  Not all programs have created allowances size correctly when creating new files so even a new file which was one copy of another (100 MB) can be fragmented over 30 times in a NTFS FS relatively fully defragmented.

    Microsoft?  HOW DO DISABLE YOU THE USN JOURNAL IN WINDOWS 7?  Not "How can I clear this" or "how stuck junk to existing articles"...  How is it DISABLED?

    -FRUSTRATED

    fsutil usn [deletejournal] {/D | / n}

    Of http://technet.microsoft.com/en-us/library/cc788042 (WS.10) .aspx

    However, I am sure that you can not turn it off for the system volume.

    You will get a response from Microsoft here.

    Just one extra point. I guess that you are talking about the \$Extend\$UsnJrnl:$J metafile; It is a fragmented NTFS file. The oldest entries are reset to zero while the file increases so they don't take any physical disk space. Actually used disk space may not exceed greatly MaxSIze + DeltaAllocation.

    http://msdn.Microsoft.com/en-us/library/aa363877 (v = VS. 85) .aspx

  • ASA NAT to 8.4

    I'm doing the VPN tunnel between router IOS and ASA 5505. The ASA has a dynamic IP address

    Everything would be ok, but I don't understand NAT in ASA's new orders. Can you tell me how to convert it to version 8.3 - 4?

    access-list no. - NAT allowed extended ip 10.1.1.0 255.255.255.0 10.2.1.0 255.255.255.0

    Global 1 interface (outside)

    NAT (inside) - No. - NAT 0 access list

    NAT (inside) 1 0.0.0.0 0.0.0.0

    I use this link

    http://www.Cisco.com/c/en/us/support/docs/security/PIX-500-series-Securi...

    Thanks for any help.

    Take a look at the document, depending on where you can find almost everything on the new model of NAT:

    https://supportforums.Cisco.com/document/132066/ASA-NAT-83-NAT-operation-and-configuration-format-CLI

    Especially "NAT0 / NAT Exemption / identity NAT ' in part"TWICE-NAT-MANUAL-NAT"is relevant for this task.

  • I installed the photoshop of 2015 and the icons are huge. I can't use the preferences because the page is too large to navigate. How can I solve this problem?

    I installed the photoshop of 2015 and the icons are huge. I can't use the preferences because the page is too large to navigate. How can I solve this problem?

    Set the user interface of the scale to 100% in your preferences and restart Photoshop.

  • VPN Cisco ASA 5540 L2L - one-way traffic only for the pair to a network

    Hello

    I'm a little confused as to which is the problem. This is the premise for the problem I have face.

    One of our big clients has a Cisco ASA5540 (8.2 (2)) failover (active / standby). Early last year, we have configured a VPN from Lan to Lan to a 3rd party site (a device of control point on their end). He worked until early this week when suddenly the connection problems.

    Only 1 of the 3 networks the / guests can access a remote network on the other side. 2 others have suddenly stopped working. We do not know of any change on our side and the remote end also insists that their end configurations are correct (and what information they sent me it seems to be correct)

    So essentially the encryption field is configured as follows:

    access-list line 1 permit extended ip 10.238.57.21 host 10.82.0.202 (hitcnt = 2)
    access-list line 2 extended permit ip 10.207.0.0 255.255.0.0 10.82.0.200 255.255.255.252 (hitcnt = 198)
    access-list line 3 extended permit ip 10.231.191.0 255.255.255.0 10.82.0.200 255.255.255.252 (hitcnt = 173)

    Free NAT has been configured as follows (names modified interfaces):

    NAT (interface1) 0-list of access to the INTERIOR-VPN-SHEEP

    the INTERIOR-VPN-SHEEP line 1 permit access list extended ip 10.231.191.0 255.255.255.0 10.82.0.200 255.255.255.252
    permit for Access-list SHEEP-VPN-INSIDE line lengthened 2 ip host 10.238.57.21 10.82.0.202

    NAT (interface2) 0-list of access VPN-SHEEP

    VPN-SHEEP line 1 permit access list extended ip 10.207.0.0 255.255.0.0 10.82.0.200 255.255.255.252

    After the problem started only 10.207.0.0/16 network connections worked for the site remote 10.82.0.200/30. All other connections do not work.

    There has been no change made on our side and on the side remote also insists there has been no change. I also checked how long the ASAs have been upward and how long the same device has been active in the failover. Both have been at the same time (about a year)

    The main problem is that users of the 10.231.191.0/24 cant access remote network network. However, the remote user can initiate and implement the VPN on their side but usually get any return traffic. Ive also checked that the routes are configured correctly in the routers in core for the return of their connections traffic should go back to the firewall.

    Also used of "packet - trace" event raising the VPN tunnel (even if it passes the phases VPN). For my understanding "packet - trace" alone with the IP source and destination addresses must activate the VPN connection (even if it generates no traffic to the current tunnel).

    This is printing to the following command: "packet - trace entry interface1 tcp 10.231.191.100 1025 10.82.0.203 80.

    Phase: 1
    Type: ACCESS-LIST
    Subtype:
    Result: ALLOW
    Config:
    Implicit rule
    Additional information:
    MAC access list

    Phase: 2
    Type: FLOW-SEARCH
    Subtype:
    Result: ALLOW
    Config:
    Additional information:
    Not found no corresponding stream, creating a new stream

    Phase: 3
    Type:-ROUTE SEARCH
    Subtype: entry
    Result: ALLOW
    Config:
    Additional information:
    in 10.82.0.200 255.255.255.252 outside

    Phase: 4
    Type: ACCESS-LIST
    Subtype: Journal
    Result: ALLOW
    Config:
    Access-group interface interface1
    access-list extended allow ip 10.231.191.0 255.255.255.0 10.82.0.200 255.255.255.252
    Additional information:

    Phase: 5
    Type: IP-OPTIONS
    Subtype:
    Result: ALLOW
    Config:
    Additional information:

    Phase: 6
    Type: INSPECT
    Subtype: np - inspect
    Result: ALLOW
    Config:
    class-map inspection_default
    match default-inspection-traffic
    Policy-map global_policy
    class inspection_default
    inspect the http
    global service-policy global_policy
    Additional information:

    Phase: 7
    Type: FOVER
    Subtype: Eve-updated
    Result: ALLOW
    Config:
    Additional information:

    Phase: 8
    Type: NAT-FREE
    Subtype:
    Result: ALLOW
    Config:
    NAT-control
    is the intellectual property inside 10.231.191.0 255.255.255.0 outside 10.82.0.200 255.255.255.252
    Exempt from NAT
    translate_hits = 32, untranslate_hits = 35251
    Additional information:

    -Phase 9 is a static nat of the problem to another network interface. Don't know why his watch to print.

    Phase: 9
    Type: NAT
    Subtype: host-limits
    Result: ALLOW
    Config:
    static (interface1, interface3) 10.231.0.0 10.231.0.0 255.255.0.0 subnet mask
    NAT-control
    is the intellectual property inside 10.231.0.0 255.255.0.0 interface3 all
    static translation at 10.231.0.0
    translate_hits = 153954, untranslate_hits = 88
    Additional information:

    -Phase 10 seems to be the default NAT for the local network configuration when traffic is to the Internet

    Phase: 10
    Type: NAT
    Subtype:
    Result: ALLOW
    Config:
    NAT (interface1) 5 10.231.191.0 255.255.255.0
    NAT-control
    is the intellectual property inside 10.231.191.0 255.255.255.0 outside of any
    dynamic translation of hen 5 (y.y.y.y)
    translate_hits = 3048900, untranslate_hits = 77195
    Additional information:

    Phase: 11
    Type: VPN
    Subtype: encrypt
    Result: ALLOW
    Config:
    Additional information:

    Phase: 12
    Type: VPN
    Subtype: ipsec-tunnel-flow
    Result: ALLOW
    Config:
    Additional information:

    Phase: 13
    Type: IP-OPTIONS
    Subtype:
    Result: ALLOW
    Config:
    Additional information:

    Phase: 14
    Type: CREATING STREAMS
    Subtype:
    Result: ALLOW
    Config:
    Additional information:
    New workflow created with the 1047981896 id, package sent to the next module

    Result:
    input interface: interface1
    entry status: to the top
    entry-line-status: to the top
    output interface: outside
    the status of the output: to the top
    output-line-status: to the top
    Action: allow

    So, basically, the connection should properly go to connect VPN L2L but yet is not. I tried to generate customer traffic of base (with the source IP address of the client network and I see the connection on the firewall, but yet there is absolutely no encapsulated packets when I check "crypto ipsec to show his" regarding this connection VPN L2L.) Its almost as if the firewall only transfers the packets on the external interface instead of encapsulating for VPN?

    And as I said, at the same time the remote end can activate the connection between these 2 networks very well, but just won't get any traffic back to their echo ICMP messages.

    access-list extended allow ip 10.231.191.0 255.255.255.0 10.82.0.200 255.255.255.252
    local ident (addr, mask, prot, port): (10.231.191.0/255.255.255.0/0/0)
    Remote ident (addr, mask, prot, port): (10.82.0.200/255.255.255.252/0/0)
    current_peer: y.y.y.y

    #pkts program: encrypt 0, #pkts: 0, #pkts digest: 0
    #pkts decaps: 131, #pkts decrypt: 131, #pkts check: 131
    compressed #pkts: 0, unzipped #pkts: 0
    #pkts uncompressed: 0, comp #pkts failed: 0, #pkts Dang failed: 0
    success #frag before: 0, failures before #frag: 0, #fragments created: 0
    Sent #PMTUs: 0, #PMTUs rcvd: 0, reassembly: 20th century / of frgs #decapsulated: 0
    #send errors: 0, #recv errors: 0

    If it was just a routing problem it would be a simple thing to fix, but it is not because I can see the connection I have to confirm it by the router base on the firewall, but they don't just get passed on to the VPN connection.

    Could this happen due to a bug in the Software ASA? Would this be something with Checkpoint VPN device? (I have absolutely no experience with devices of control point)

    If there is any essential information that I can give, please ask.

    -Jouni

    Jouni,

    8.2.4.1 is the minimum - 8.2.4 had some issues (including TCP proxy).

    If this does not resolve the problem - I suggest open TAC box to get to the bottom of this ;-)

    Marcin

  • Do magsafe pin burn because of the fluctuation of power?

    Hello

    I have end of 2013 Macbook Pro (retina) that I bought in the USA. Now, I use it in India.

    One of the pins of the power adapter 85W Magsafe 2 is burned and glued. It's the tiny pin next to the great.

    Corresponding connector in the laptop also get burned.

    To power the laptop, I attach and detach the magsafe several times to make it work. This is due to

    power fluctuation? The magsafe also get very hot when the laptop support.

    If it's because of the fluctuation of power, I can use "voltage stabilizer" or UPS?

    Please, give me suggestion to solve this problem.

    Thanks in advance,

    Jay

    WeAreStardust wrote:

    Hello

    I have end of 2013 Macbook Pro (retina) that I bought in the USA. Now, I use it in India.

    One of the pins of the power adapter 85W Magsafe 2 is burned and glued. It's the tiny pin next to the great.

    Corresponding connector in the laptop also get burned.

    To power the laptop, I attach and detach the magsafe several times to make it work. This is due to

    power fluctuation? The magsafe also get very hot when the laptop support.

    If it's because of the fluctuation of power, I can use "voltage stabilizer" or UPS?

    Please, give me suggestion to solve this problem.

    Thanks in advance,

    Jay

    Voltage stabilizer is always good if you always dirty power.  It causes burning pine? I don't see how unless the connection is not so good PIN-to-pin. Spikes can cause this.

  • Java has been blocked because of the threat, I did the update, and other options to reactivate it ie.manual update reinstalls still websites like YouTube always used to load up. Works great in Chrome & IE!

    Java has been blocked because of the threat, I did the update, and other options to reactivate it ie.manual update reinstalls still websites like YouTube always used to load up. Works great in Chrome & IE!

    Your list of plugins in "Details of the system more" Watch 1.6.0_31 of next generation Java plug-in for browsers Mozilla for Java should not be blocked.

    Could you post a link to a Web page where Java does not work for you? YouTube uses the Flash, not Java. Here is a list of the test pages of Java that you can try to verify that Java works, of http://kb.mozillazine.org/Java#Testing_Java

    Moreover, I see in your list of plugins you also the VLC media player Plugin Web 2.0.0 so, it is possible that the VLC plugin is causing a conflict if YouTube or other videos do not work. See Fix common audio and graphics problems (you may have to disable the VLC Media Player plugin in the Add-ons-> list of Plugins for some media to play).

  • HELPPP... I lost my e mail account because of the pirates

    HELPPP... I lost my e mail because of the hackers.microsoft account will not help me cause I don't remember all the details, that does.even I answered security question .wat else.i lost m

    You can help this is so important

    If you don't remember the details, you are out of luck, aren't you? And if MS will not help you because you have forgotten the details, which devil do you can?

    View all Windows Live and Hotmail questions in the appropriate forum found here:
    http://windowslivehelp.com/

  • Recently lost data because of the "Windows Recovery" XP virus

    Greetings,
    I have recently all my data because of the virus: "Windows Recovery. When I go to start, programs. everything is gone, also no photos, videos or music. I tried to restore the system to a different date, but it won't let me.  Moreover, the basket is empty. I removed the virus using "Malwarebytes... but impossible to recover the files. Please, any advice >
    Eric

    Hi Tropicguy,

    Like JoseIbarra said, it could be that the virus has caused your folders/files/programs show hidden.  I suggest checking to see if they are there, after doing the following:

    http://www.Microsoft.com/resources/documentation/Windows/XP/all/proddocs/en-us/WIN_FCAB_SHOW_FILE_EXTENSIONS.mspx?mfr=true

    I hope this helps!

  • I can't install Microsoft. NET Framework 4.0 because of the error (0xC8000222)

    I can't install Microsoft. NET Framework 4.0 because of the error (0xC8000222), so for this reason, I can't install Kaspersky Internet Security 2015, suggestions...

    Hi Ryan,

    Thanks for posting your query in Microsoft Community.

    I understand that you can not install .net Framework 4.0 whereby you are unable to install the Kaspersky Internet Security software and I'll be happy to answer your query. Let me ask you;

    • How you try to install .net Framework 4.0?
    • Are you can install other updates?
    • What is the exact error message that you receive when installing .net Framework 4.0?
    • Is there any previous Internet Security installed on the computer software?

    There could be several reasons for not being able to install any program or update including any third-party software conflict, corruption of Windows Installer, Windows updates the corruptions of components etc. Please, try the following methods and check.

    Method 1: If you try to install .net Framework through updates, try using the Windows Update Troubleshooter to fix the problem. He makes sure your computer is connected to the Internet and checks to see if your network card and Windows Update services are running properly.

    Method 2: Put the computer in a clean boot state and check.

    To help resolve the error and other messages, you can start Windows by using a minimal set of drivers and startup programs. This type of boot is known as a "clean boot". A clean boot helps eliminate software conflicts.

    Place your system in the clean boot state helps determine if third-party applications or startup items are causing the problem. You must follow the steps in the article mentioned below to perform a clean boot.

    How to perform a clean boot in Windows

    Note: see 'How do I reset the computer to start normally after a boot minimum troubleshooting' to reset the computer starts normally after troubleshooting.

    Method 3: You can reset the Windows Update components and check the status.

    To automatically reset the Windows Components update, run the fixit in the article below. If the Fixit does not work, you can try the manual steps and check.

    How to reset the Windows Update components?

    Method 4: Fix the .NET Framework

    Download the Microsoft .NET Framework repair tool to repair the following versions of the .NET Framework, and then reinstall the update of the .NET Framework.

    Method 5: Uninstall and reinstall the .NET Framework

    To do this, follow these steps:

    1. Discover the .NET Framework Cleanup Tool User Guide.
    2. Download the .NET Framework cleanup tool.
    3. When you are prompted, click Open, and then click retrieve now.
    4. In which you extracted the files, double-click cleanup_tool.exe.

    If you are prompted for an administrator password or for confirmation, provide the password, and then click continue.
  • In the Do you want to run the .NET Framework Setup Cleanup Utility? message, click Yes.
  • Click Yes to accept the license agreement.
  • In the window cleaning product , click the list, select .NET Framework - all Versionsand then click clean up now.
    Note the cleaning tool does not remove the .NET Framework 2.0 in Windows Vista or later versions of Windows because the .NET Framework is installed as a component of the operating system.
  • After the .NET Framework is removed, restart the computer.
  • Download and install the following components:
  • The .NET Framework 3.5 Service Pack 1 (this will also install the .NET Framework 2.0 SP2 and the .NET Framework 3.0 SP2)

  • Restart the computer.
  • Visit Windows Update again, and then review and install the updates.
  • Try to reinstall the update of the .NET Framework.
  • Hope this information is useful. Please feel free to answer in the case where you are facing in the future other problems with Windows.

  • ASA 5520 8.0 (4) port depending on the ACLs vpn works not

    Hi all

    I have a problem with an ASA (5520 8.0 (4)) for lack of working with a port based acl for remote clients. I have a simple acl from a single line to split traffic, if I allowed the tunnel IP works fine, if I lock it up to TCP 3389 rdp will not work. I don't see anything in the logs and debug output, I did have a problem with a similar configuration (5510 8.0 (4) and I'm at a loss to explain it.)

    Everyone knows about this problem before? I have nat exclusions etc and as I said, the tunnel only works if the acl permits all IP traffic between client and server.

    THX in advance

    Split-tunnel list cannot IP, if you want to restrict which ports are are sent via the tunnel vpn for your clients vpn, you need to use VPN filters under Group Policy:

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml

  • Dynamics Processor Calc does not reach more than [100] ESM blocks during the calculation, please increase the CalcLockBlock setting, and then try again (a small data cache setting can also cause this problem, check the size of data cache setting).

    Hello

    Our environment is Essbase 11.1.2.2 and work on Essbase EAS and components of Shared Services. One of our user tried to execute the Script of Cal of a single application and in the face of this error.

    Dynamics Processor Calc does not reach more than [100] ESM blocks during the calculation, please increase the CalcLockBlock setting, and then try again (a small data cache setting can also cause this problem, check the size of data cache setting).


    I did a few Google and found that we need to add something in the Essbase.cfg file as below.

    Dynamics Processor Calc 1012704 fails to more blocks ESM number for the calculation, please increase the CalcLockBlock setting, and then try again (a small data cache setting can also cause this problem, check the size of data cache setting).

    Possible problems

    Analytical services cannot lock enough blocks to perform the calculation.

    Possible solutions

    Increase the number of blocks of analytical Services can allocate to a calculation:

    1. Set the maximum number of blocks of analytical Services can allocate at least 500.
      1. If you are not a $ARBORPATH/bin/essbase.cfg on the file server computer, create one using a text editor.
      2. In the essbase.cfg folder on the server computer, set CALCLOCKBLOCKHIGH to 500.
      3. Stopping and restarting Analysis server.
    2. Add the command SET LOCKBLOCK STUDENT at the beginning of the calculation script.
    3. Set the cache of data large enough to hold all the blocks specified in the CALCLOCKBLOCKHIGH parameter.

    In fact in our queue (essbase.cfg) Config Server we have given below added.

    CalcLockBlockHigh 2000

    CalcLockBlockDefault 200

    CalcLockBlocklow 50


    So my question is if edit us the file Essbase.cfg and add the above settings restart services will work?  and if yes, why should change us the configuration file of server if the problem concerns a Cal Script application. Please guide me how to do this.


    Kind regards

    Naveen

    Yes it must *.

    Make sure that you have "migrated settings cache of database as well. If the cache is too small, you will have similar problems.

  • Invalid environment because of the previous exception

    Hi, my program that runs a long time suddenly occur an error, the following message appears:
    java.lang.RuntimeException: invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 46 lsn = 0 x 0/0x205c69 logSource=com.sleepycat.je.log.FileHandleSource@568ee2b9
    + wisers.crawler.batch.store.ArticleStoreImpl.contains(ArticleStoreImpl.java:63) +.
    + wisers.crawler.batch.extractor.ListingExtractor.extract(ListingExtractor.java:93) +.
    + wisers.crawler.batch.processor.CrawlWorkerImpl.execute(CrawlWorkerImpl.java:276) +.
    + wisers.crawler.batch.schedule.JobManager$ Runner$ 1.run(JobManager.java:73) +.
    + java.util.concurrent.Executors$ (Executors.java:441) RunnableAdapter.call +.
    + java.util.concurrent.FutureTask$ (FutureTask.java:303) Sync.innerRun +.
    + java.util.concurrent.FutureTask.run(FutureTask.java:138) +.
    + java.util.concurrent.ThreadPoolExecutor$ (ThreadPoolExecutor.java:886) Worker.runTask +.
    + java.util.concurrent.ThreadPoolExecutor$ (ThreadPoolExecutor.java:908) Worker.run +.
    + java.lang.Thread.run(Thread.java:662) +.
    Caused by: invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 46 lsn = 0 x 0/0x205c69 logSource=com.sleepycat.je.log.FileHandleSource@568ee2b9
    + com.sleepycat.je.log.LogEntryHeader. (LogEntryHeader.java:94) +.
    + com.sleepycat.je.log.LogManager.getLogEntryFromLogSource(LogManager.java:699) +.
    + com.sleepycat.je.log.LogManager.getLogEntry(LogManager.java:664) +.
    + com.sleepycat.je.tree.IN.fetchTarget(IN.java:1215) +.
    + com.sleepycat.je.dbi.CursorImpl.fetchCurrent(CursorImpl.java:2320) +.
    + com.sleepycat.je.dbi.CursorImpl.getCurrentAlreadyLatched(CursorImpl.java:1427) +.
    + com.sleepycat.je.dbi.CursorImpl.getNextWithKeyChangeStatus(CursorImpl.java:1573) +.
    + com.sleepycat.je.dbi.CursorImpl.getNext(CursorImpl.java:1499) +.
    + com.sleepycat.je.cleaner.UtilizationProfile.getObsoleteDetail(UtilizationProfile.java:953) +.
    + com.sleepycat.je.cleaner.FileProcessor.processFile(FileProcessor.java:326) +.
    + com.sleepycat.je.cleaner.FileProcessor.doClean(FileProcessor.java:233) +.
    + com.sleepycat.je.cleaner.FileProcessor.onWakeup(FileProcessor.java:138) +.
    + com.sleepycat.je.utilint.DaemonThread.run(DaemonThread.java:141) +.
    +     ... more 1 +.


    After that, I use com.sleepycat.je.util.DbVerify try to examines the identified database to find errors, the following information:
    Checking database wm_cyolcn
    Tree for wm_cyolcn control
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x205e59 parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d30382f31392f636f6e74656e745f343739363335312e68746d http://health.cyol.com/content/2011-08/19/content_4796351.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x23110a parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d30382f31392f636f6e74656e745f343739363335332e68746d http://health.cyol.com/content/2011-08/19/content_4796353.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x230efd parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d30382f31392f636f6e74656e745f343739363935342e68746d http://health.cyol.com/content/2011-08/19/content_4796954.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x235d78 parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d30382f31392f636f6e74656e745f343739373039382e68746d http://health.cyol.com/content/2011-08/19/content_4797098.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x235b6b parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d30382f32392f636f6e74656e745f343833323435352e68746d http://health.cyol.com/content/2011-08/29/content_4832455.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x343eda parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31302f32362f636f6e74656e745f353037363133322e68746d http://health.cyol.com/content/2011-10/26/content_5076132.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x343d7c parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31322f32302f636f6e74656e745f353338383837322e68746d http://health.cyol.com/content/2011-12/20/content_5388872.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x4004f2 parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31322f32322f636f6e74656e745f353430353431352e68746d http://health.cyol.com/content/2011-12/22/content_5405415.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0 / 0 x 400394 IN parent = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31322f32322f636f6e74656e745f353430383033302e68746d http://health.cyol.com/content/2011-12/22/content_5408030.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x4026d3 parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31322f32322f636f6e74656e745f353430383033322e68746d http://health.cyol.com/content/2011-12/22/content_5408032.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x4069fd parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31322f32362f636f6e74656e745f353432383330312e68746d http://health.cyol.com/content/2011-12/26/content_5428301.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x4067f0 parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31322f32362f636f6e74656e745f353432383431302e68746d http://health.cyol.com/content/2011-12/26/content_5428410.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x40cd5e parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31322f33302f636f6e74656e745f353436313733372e68746d http://health.cyol.com/content/2011-12/30/content_5461737.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x4110dd parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031312d31322f33312f636f6e74656e745f353436393237382e68746d http://health.cyol.com/content/2011-12/31/content_5469278.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x4136bf parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    Error touch 687474703a2f2f6865616c74682e63796f6c2e636f6d2f636f6e74656e742f323031322d30312f30362f636f6e74656e745f353439313038392e68746d http://health.cyol.com/content/2012-01/06/content_5491089.htm
    UNKNOWN error data
    Encountered error (continuous):
    com.sleepycat.je.DatabaseException: (I 3.3.82) fetchTarget 0 x 0/0x4738d2 parent IN = 2281 IN class = com.sleepycat.je.tree.BIN lastFullVersion = 0 x 0/0x4adf10 parent.getDirty () = State false = 0 invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    UNKNOWN error key
    UNKNOWN error data
    numBottomInternalNodes = 103
    level 1: count = 103
    numInternalNodes = 3
    level 2: count = 2
    level 3: count = 1
    numLeafNodes = 6620
    numDeletedLeafNodes = 0
    numDuplicateCountLeafNodes = 0
    mainTreeMaxDepth = 3
    duplicateTreeMaxDepth = 0

    Invalid environment because of the previous exception: com.sleepycat.je.log.DbChecksumException: (I 3.3.82) read the type of invalid log entry: 108 lsn = 0 x 0/0x205e59 logSource=com.sleepycat.je.log.FileHandleSource@5210f6d3
    to com.sleepycat.je.log.LogEntryHeader. < init > (LogEntryHeader.java:94)
    at com.sleepycat.je.log.LogManager.getLogEntryFromLogSource(LogManager.java:699)
    at com.sleepycat.je.log.LogManager.getLogEntry(LogManager.java:664)
    at com.sleepycat.je.tree.IN.fetchTarget(IN.java:1215)
    at com.sleepycat.je.dbi.CursorImpl.fetchCurrent(CursorImpl.java:2320)
    at com.sleepycat.je.dbi.CursorImpl.getCurrentAlreadyLatched(CursorImpl.java:1427)
    at com.sleepycat.je.dbi.CursorImpl.getNextWithKeyChangeStatus(CursorImpl.java:1573)
    at com.sleepycat.je.dbi.CursorImpl.getNext(CursorImpl.java:1499)
    at com.sleepycat.je.dbi.DatabaseImpl.walkDatabaseTree(DatabaseImpl.java:1355)
    at com.sleepycat.je.dbi.DatabaseImpl.verify(DatabaseImpl.java:1303)
    at com.sleepycat.je.util.DbVerify.verifyOneDbImpl(DbVerify.java:371)
    at com.sleepycat.je.util.DbVerify.verify(DbVerify.java:275)
    at com.sleepycat.je.util.DbVerify.main(DbVerify.java:94)
    Exit code = false

    I want to know, the db file can repair? And how do I?
    Thank you very much!

    I hope that the DbDump and DbLoad utilities willl help recover you and reload your data. Start at http://docs.oracle.com/cd/E17277_02/html/GettingStartedGuide/commandlinetools.html#DbDump, or with DbDump http://docs.oracle.com/cd/E17277_02/html/java/com/sleepycat/je/util/DbDump.html and first try the-r, then the options - R.

Maybe you are looking for