Number of licenses of PIX

I noticed a strange activity with regard to the user with the PIX license features.

I have two networks interconnected via VPN. One side is a 515 (unrestricted) the other is a 501 (50 users). I noticed that if I do a scan of ICMP ping against the 501 internal network IP range, I use all licenses of connection on their PIX, even if I have only 30 physical machines on that network.

This seems a little strange to me. Anyone encountered this before? Even if no computer used the majority of the address space that has been surveyed, the PIX takes each IP address as a user license and restricted access for all connections more.

I think it would have been more logical to expect an ARP entry is created successfully to be able to count against the license of the user on the device. Someone at - he comments?

Kind regards

-Joshua

It is an expected behavior, although some might say it's a little weird.

The ping packet is allowed through because it is part of the VPN tunnel (I guess you have the command "sysopt connection permit-ipsec" in place which allows any package IPSec in). As the packet passes through the PIX and a conn/xlate is created, the PIX legitimately consumes a license for it, regardless of whether the package is actually answered or not. Change this behavior would change the entire concept of the licensing operation. Note that this wouldn't happen if someone on the Internet (not on the VPN tunnel) did a ping sweep, cause the package would have fallen to the external interface and no xlate/conn would be created for her.

You could lower your xlate/conn timeout to 5 minutes, or how they'll expire faster and free licenses, but at this stage the PIX does what he is told to do and it is to use a license for a host with an xlate/conn. Unfortunately with him coming in via a VPN, has no way for him to say if this host is really or does not before creating the xlate/conn.

Tags: Cisco Security

Similar Questions

Maybe you are looking for

  • Block of stimulus response SR

    Salvation in the article http://sine.NI.com/NP/app/main/p/AP/MI/lang/en/PG/1/SN/n17:MI, n21:155/fmid/2947. high-speed digital and stimulus response features ATE, there is a good example of test a SRAM I / C which is the closest example of you I've se

  • versions SCXI-1349

    Hello everyone, I have a doubt. In the past, I'm sure I saw a document (on site or Devzone, but I can't find it now easily), where I read that it is necessary to choose the different versions of the SCXI-1349 module, when you use this card, connected

  • Neverwinter Nights Diamond windows compatibility problems

    Origianal title: Neverwinter Nights Diamond works with Vista?  If yes how to operate?  It works with Windows 7?  If so, how? Thank you Finally after many years and several accidents have completed Baldurs Gate II and Throne of Bhaal.  Bought Neverwin

  • forgot my password for my advent 9115

    and cannot log in can someone help please

  • WINDOWS SECURITY POP UP PROBLEM

    Help! Approximately four to five days before, my internet started to appear this window that says "windows security - the content that you are about to see not all sent safely. Do you want to display only the secure http content? "that is not verbati