PIX TTL values decreasing

This of course sounds abnormal. External interface of ping PIX,

$ ping 195.x.x.x

PING 195.x.x.x (195.x.x.x): 56 bytes

64 bytes from 195.x.x.x: icmp_seq = 0 ttl = 246 time = 7,393 ms

However, if I ping a box in the DMZ, things seem a little weird.

$ ping 195.x.x.x

PING 195.x.x.x (195.x.x.x): 56 bytes

64 bytes from 195.x.x.x: icmp_seq = 0 ttl = 55 time = 11,852 ms

I'm under 6.3 (1). I don't remember this behavior on earlier versions. If something has changed in the latest version.

Pointers are welcome.

I do not see why the PIX would decrement the values you seem when the ICMP packet passes through the PIX on the DMZ segment. My first guess would be that maybe the response to ICMP echo packet that you see in 195.x.x.x in the DMZ network does not take the same path as the package that strikes the PIX interface itself.

I would check the routing on the network and the DMZ itself host information. If this does not give you the answer, I would use the command "debug icmp trace" on the PIX to verify that in fact the echo and echo response is going through the PIX. You can also verify the ICMP packet with this debug information.

I hope this helps...

Marcus

Tags: Cisco Security

Similar Questions

  • How to make a value decrease of time, at intervals of one second

    Hello, I am working with an Agilent N5181A to send a command from my code. I've set up the frequency, and now I want to be able to change the value of the amplitude. Right now I have a constant set to-30 and I want to replace it so that it passes from-30 to-80-10 intervals every second.

    For example:

    -30

    -40

    -50

    etc.

    so that in the end, I reached-80, I have attached a screenshot to understand, thank you.

    The frequency setting, it's what you pass to the value of frequency control. How often you update the voltage depends on the waiting period. You said you wanted 1 second intervals. That's why I used 1000 msec in the example. Of course you should not put all the code in the loop. Just as the tension and everything what you need (i.e. a measure).

    The stop is a control. If you do not know how to create a control on the front panel, you might want to go back and very basic LabVIEW tutorials and review them.

    The timeout value is what you want. You said that you wanted to have the values decrease--30 to 80. If this is what you want, use a value of-80 in the control. If you want to stop at-90, enter.

  • Back on the cisco ASA 5500 series and PIX 500 series

    Hello

    I fund a site www http://www.searchsecurity.de/themenkanaele/plattformsicherheit/schwachstellenmanagement/allgemein/articles/106752/ (only in German). I have read that it is possible to make a denial of service on cisco PIX 500 series and series 5500 ASA, when the TTL value is enabled.

    How can I check that? or solve the problem?

    I thank you,

    Mary

    What version of the code you run the Pix or ASA. Refer to the "Products affected" section for more information on versions and the products concerned. This should point you in the right direction.

    Also, listed in the URL is bypasses and fixed Versions that you may want to check.

    Kind regards

    Arul

  • Why is-36 of Firefox on Windows receiving connections from DNS servers? Option network.dns.get - ttl

    Following update Firefox 36, my firewall was flooding asking me to allow external connections from the Internet to my browser. Looking at it more closely, Comodo Firewall indicates that external websites are trying to connect to Firefox, port 53 to an arbitrary port on my machine.

    If I disable the option FF36 new network.dns.get - ttl, it stops. I can't find any documentation or help on this option.

    Why Firefox do this? Is Comodo incorrect when he labels it as an external connection attempt? (It has normally been extremely good to differentiate the incoming and outgoing traffic). I guess that Firefox is trying to determine the TTL for DNS caching, but it is not make sense why DNS servers then try to connect to me.

    I am reluctant to create a firewall rule to that arbitrary Internet connections on my machine are OK as long as their origin on port 53, tips on how to manage all that this new feature is firmly States would be appreciated.

    Thanks in advance for any help.

    Hi grammarye,

    Yes, you're right in thinking that Firefox is trying to find the TTL value. This is new in Firefox 36 behavior and was presented as services frequently changing DNS records (such as Cloudflare) were not working properly for Firefox users.

    Firefox makes asynchronous DNS searches - which means it will make a DNS query and then proceed to perform another task instead of waiting for an answer.

    Your ISP DNS server puts in cache only TTL an area for a short time, so if it does not the current LIFE expectancy, he will interview with other DNS servers to find.

    IANAE, but probably what is happening is:

    1. Firefox tries to find the DNS record for the domain that you want to connect to
    2. Your ISP DNS server does not have the current LIFE expectancy, then connects with other DNS servers to find
    3. During this time, Firefox lingers with something else
    4. DNS server, then reconnects to give you full DNS, including the TTL check
    5. Comodo sees the packets of the DNS server and panic

    I completely agree that arbitrary ports of white list is a bad idea, but in this case, the behavior is completely harmless.

    You can want to whitelist Firefox in your Comodo Firewall, or continue to let network.dns.get - disabled ttl.

    (edited to fix broken links and add a sentence)

  • external TTL sync

    I need to synchronize a sine output to an input ttl (1 kHz).  Basically, I need to turn a ttl input in a sinusoidal output running at the same frequency (or a harmonic sup with adjustable phase) and amplitude.  I have a pci6221 DAQ card and a bnc breakout box, but I have not been able to get a sinusoidal output synchronized to the input ttl value.  Is there a simple way to do this before you have me fed up and break all the electronics?

    Thank you

    I found a VI that does what I need it to do

    FTP://FTP.NI.com/pub/DevZone/EPD/retriggerable_ao_0001.zip

  • min/max with outputs ttl statistics

    This is a weird problem. I have attached the worksheet because it is difficult to explain the problem. First of all, let me explain what this thing is supposed to do. A generator of signals outputs sine 5Vp - p, in addition to four. After being added, I use a module of statistics to determine the Min/Max. All I need is the maximum, the minimum is ignored (I'm only looking to the + pics). The + peaks are evaluated to identify uniquely to the final output, which sinewave (s) have been entered in the worksheet. Since I finally need 16 - bit I had to add a scalar unit (scale module) to create the entry 16 (max 15 son allowed an output) by expanding the 15th input to two outputs. I see the expected level of TTL is issued by the module of statistics on three modules Y/t diagram. This tells me that things seem a little work at the exit of the module of SEO (the values of hysteresis in the stat module need to be tweaked to produce all the unique values (16), but it works at least. The problem is that the module of bitmask (set to combine tips - 16-bit conversion for a wide release) generates no output regardless of sinewave different combinations of entry. I thought that I have had set a good example of C.J. provided. I hooked of DMM to also monitor the inputs to the module of bitmask (called 16-bit encoder) - I can't get the digital multimeter to display the output of the module of the stat, but the modules Y/t show the output TTL values there. Both show the modules expected to show which is output, but don't--that intrigues me. The frequency of the sine wave is set to 1,2,4 & 8 Hz for debugging, so I know it is not too fast for the DMM display - I proved this by connecting the sum as an input for the senior DMM sinewave and it displays the voltage changes without problem.

    Thus, the two questions are: 1) why the DMM is not working at the release of the Y/t modules or Module Min/Max of Stat?  (2) why the bitmask Module cannot evaluate its entries? The added sine wave is continuous and constant phase.

    Any help would be appreciated. This has really baffled me, trying to debug.

    It dawned on me that the DMM is placed where they will not work because they are supposed to show a too short period of tension. They would appear between 5V and 25V depending on the number of 5V wfm summary, but each TTL output, they try to show are nothing more than the duration milliseconds--not a good application for a DMM. Now, it's just a question of what is the problem with the 16-bit conversion package around!

    Any suggestions on the problem?

  • El Capitan is unable to reset DNS

    Hello

    I use 2011 27 "mac desktop. Recently, my developer changed my Web site and the server and my machine keeps using old sites DNS. My developer was blocked and asked me to give my DNS connection with this command.

    sudo dscacheutil - flushcache. sudo killall - HUP mDNSResponder. say DNS cache empty

    I tried this million times. He made the order and say DNS is empty, but nothing changes on my machine. Still cannot access my Web site.

    I have also tried to restart the browser, clear the cache, clear history etc. I tried a few other browsers as well but all the same.

    What I would do.

    Help, please.

    Thank you.

    Armands

    Well, if you have emptied your cache a bazillion times, then the most likely cause is that servers DNS, you reference don't have either not acquired the DNS update-DNS servers cache also the translations, and it can take up to the value of life (TTL, Time To Live) to propagate, or the DNS update has not been correctly and so spreading to all.

    Most people doing a cut-over site will fix the low TTL value in the day or two, leading to the cut-over to avoid this problem, if I guessed correctly about the cause of the problem.

    If your web server is named server.example.com, then the following command line commands will show what the translation is for your local cache and - if the cache was emptied - your local DNS servers have the IP address of your server, and the second command will show what Google's DNS (8.8.8.8) servers have the same translation.

    Dig + short server.example.com

    dig + short @8.8.8.8 server.example.com

    Google's DNS servers tend to capture the DNS changes fairly quickly, while some devices of bridge - those that caches the translations - and various ISP DNS servers could not or will not pick up the translation for a day or two. until the TTL expires.

    As a temporary workaround - and assuming that the Google DNS servers return to the new IP address - you can temporarily set your DNS server address (System preferences > network > select your network > advanced > DNS > 8.8.8.8 and 8.8.4.4) for a day or two. until your local caches to catch up.   Don't forget to remove these settings and to return to your DNS-DHCP-set server settings.

  • Signal steady decline

    Hello

    I use a transducer of pressure with a maximum flow of 100mV. I connected this pressure for an SCB-68 transducer that is connected to a PXI-6289. The transducer is connected in differential mode (ai0 & ai8). I'm supposed to measure a constant balance no when I turn on the transducer (10V DC) without differential pressure applied to the transducer output from - 5 mV to 5mV.

    The problem is:

    I measure a zero balance output, but the value continues to decline (even after 50 minutes). If out of balance zero is negative, the value decreases yet (he does not lean towards 0).

    If I connect two transducers on different channels, zero out of balance (which is not the same thing, according to the serial number of the transducer) will decrease at the same rate.

    What I tried:

    I tried another power supply

    I tried to measure CSR and NRSE

    I tried with another station of PXI
    I tried with BNC-2090
    I tried with the PXI-6224

    I tried with other sensors of serial number (3 different with all the same problem)

    I tried with other cables

    I tried to measure in a different location using a different power source

    I tried to reduce drastically (from 10 k to 1 sample per second), the sampling rate

    ALL these failed to solve the problem.

    I have contacted my provider of transducer. He has guaranteed that these sensors should keep their zero balance production constant for 4 years. Also, the fact that the rate of decline is almost the same thing when I connect different transducer would point to one reason other then the sensor itself.

    Here is an example of a test (about 35 minutes). The tension is out of balance zero. Unknown event caused a rapid fall in the beginning.

    Hoping to get a quick response,

    Elliot


  • USB-6009 software simultaneous timed output analog

    Ladies and gentlemen,

    I worked on a LabVIEW interface to a potentiostat I designed and built. I'm not very experienced with LabVIEW, but do they have experience with a variety of other languages (I had originally intend to use an FPGA for this, but he has been asked to write a LabVIEW VI first) programming.

    The goal:

    I want to output a voltage (initially consisting of ramps) signal and measure the voltage with an operational amplifier configured as an ammeter of feedback (using resistance feedback and voltage value to calculate current) connected to an electrochemical cell. The resistance of feedback is selected by using an automatic selection function (although I wrote a version prior to manual control) as TTL values using the DAQ Assistant to select relevant MUX channel outputs. I then try to save the data in a spreadsheet.

    The problem:

    I use an acquisition of data USB-6009, and I know that there is a hardware clock. Read all about him seemed obvious, the best way to the waveform of the output voltage used DAQmx package to define a function of writing in a loop that is clocked by the software. The problem I have is that I can't synchronize the output to the input with reliability and I have also some errors related to resources DAQ being reserved (error 50103). I think the way to solve this would be to convert every equivalent DAQmx DAQ Assistant and try to group their execution - this is where I fall. I tried to write a simple VI who shared a loop clocked by the software to read and write but had problems related to the value of min HAVE (error 200077).

    General issues:

    How I begin the process of read/write (with a Boolean switch) is very weak and doesn't feel not robust. Ideally, I would like to some form of indicator to warn the user when the read/write process is running and when it ended.

    My error handling is terrible, but I find no big thing to read about the basics.

    I use only a sequence of no and I think I should have more.

    Once I hit the beginning, VI requires the file name for the worksheet - at first, I was afraid that data would be entered correctly, but I think it's okay because the file is generated and then changed. It would be better if the user asked for the name of the file once completed the data collection.

    Any suggestion or help would be greatly appreciated. Thank you in advance.

    Sincere greetings,

    Julius

    The hardware supports timed 6009 entry analog. Even with the 1Samp mode, your code could be simplified with a single task and several channels (dev1\ai0:1). Then use Nchan 1Samp.

  • scaling problems with the DAQ hardware help

    I am a new user and I'm trying to do a simple scaling of my entries of tension using the DAQ help. For example: a channel entered around 8V on a 0 to 10V input selection. I'm trying to resize it (linear) to show me around 28V using y = mx + b formula. My value of m is 3.2 and b 0. What DAQ Assistant bed is close to 16V instead of 25V (3.2 * 8). I custom make several scales, basically multiplying the entry of 2, 3, 4, 5, & but none exits causes what I expected according to the formula, and even the 5 x the value decrease. If I go to "not to scale", I read 8V, which is what actually happens in the 6255 map. Any thoughts?

    Hello DB66.

    Remember that the scope of the input Signal must be defined scale post. How do you set as your input signal range, you're reading may be scaling themselves within the reach of the input signal. A value of coefficient of 3.2, the stove must be Max = 32 Min =-32, since your device probably has a +/-10V range.

    Hope that helps.

  • 1520 strain no reading

    Experimental set-up:

    SCXI chassis, the module of 1520, 1314 accessory; 6062E pcmcia.

    Half bridge 350 ohm (type II), and even that (checked by manual measurement with multimeter) shunt resistors. Self excitation (2, 5V).

    I want to measure the strain but cannot. When I started to acquisition, an initial value is shown, say,-200. The value decreases at a constant rate until it reaches autour-970, remains constant.

    I checked manually:

    P - P voltage +: 2.49V

    Voltage output - P: - 1.24

    Output voltage - P'+: 1.24

    Voltage at the terminals of R4: 1.24 V

    Voltage at the terminals of the R3: 1.24 V

    P + - Vout resistance: 350 ohms

    Resistance P - Vout: 350 ohm

    If I try the offset null calibration, I get error-200380 (see attachment).

    So it looks like an open circuit, but I interpret manually tension through R, what happens?

    I am amazed on the solution that I found:

    After checking with the multimeter is everything as should be, I changed full bridge configuration in order to access with the meter at each point in the bridge and provide measures.

    Everything was going fine manually but still not in LV

    So, after a while, I changed .vi DAQmx Read of multiple channels of wave rippling single channel, as I was measuring only one channel.

    Now everything works fine.

    I am amazed, I supoused that channel Multiple consisted only a single channel.

  • IPv4 NAT in IPV6 for Internet access

    Advanced thanks.

    New Internet transport is incoming.

    IPv4 and 6 addresses are available for use.

    A notion exists that any V4 address assigned to we were able to be used elsewhere and is, therefore, a security risk potential (I have trouble understanding this fear. Please do not hesitate to comment be it).

    He is asked if it is possible to NAT the address private to a supplied bracket V6 public address range.

    I've read so far no indication that this is possible.

    If anyone knows otherwise, I welcome your comments.

    Thank you

    IPv4 and 6 addresses are available for use.

    Well Yes.  V6 is more than 50% of the data traffic of cell LTE4 in the United States, more than 40% of traffic in backbone of the Belgium, tends to work better than the v4 for mobile devices, etc.  It's true.  We are in the interregnum of double-internet, where not all clients can talk to all servers, until the transition of the v6 is over 15 years.

    ... no matter what V4 address assigned to we were able to be used elsewhere and is, therefore, a potential security risk

    Because the IPv4 address space is commonly used around the world, most ISP are turning to 'carrier grade NAT' where customers share the overall scope of intellectual to a NAT upstream.  The reputation of the internet of such middlebox will trend down in the most infected client / badly behaved behind it, which is always going to be a zombie botnet.  Could collateral damage to the protocols used by perfectly well-behaved clients that also share the catwalk of the GNC.

    During this time, you can not new the regional internet registrys IPv4 subnets, so your only effective source of additional IP space is to pay for a transfer to someone else.  The transferred subnet was probably already in use and so can be on blacklists to email spamming or have blackhole routes to the backbone of the ISP.  He could have previously also housed nuisance attractive such as banking or services of Paris that are often being DDOSd because of the inertia of the miscreant.  This can take time and effort to clean.

    Recycled IPv4 addresses that are actually working for you are not particularly more at risk than the addresses of archaic origin question from a security point of view; mainly, endpoint software quality-controlled not by mere reputation.

    [it is] NAT possible range of addresses private to a supplied bracket V6 sound

    Sort of.  The usual problem is that a client v6 only (say, a cellphone LTE4) tries to join a v4 service only (for example, a typical business web site).  This requires 6--> 4 translation; for that this week the default mechanism seems to be "464xlat".  The customer gets two v6/64 prefixes, transport v6 only and a private address v4 which is in tunnel on the secondary prefix to a carrier grade NAT64/DNS64 middlebox.

    The inverse problem of a customer only v4 trying to reach the Server v6 only is usually academic; usually you dual-stack to the client instead and there aren't many services only v6, although this will change.

    The IETF has downgraded RFC 2766 NAT - PT for the translation of v4 to v6 historical belonging, meaning it is not recommended for use on the internet in general, in the RFC 4966.  In addition to all the usual problems of NAT, NAT - PT does not work across ISPS due to the inability to get the right DNS46 TTL values.  If you try only translate a small subnet of a single body, say a v4/24, you might be able to find a software that did it, but it's the wrong way to take.

    If the problem is that the customer support not double stack v4 + v6, switch to something produced in this century; even windows XP can be dual-Stack if offer you it DNS on v4.

    If the problem is the ISP offer v6-transport, tunnel traffic v4 across this gap v6 to a double gateway to battery.

    -Jim Leinweber, WI State Lab of hygiene

  • IR_REPORT URL does not not as expected

    Apex v4.2.2.00.11 on Oracle RAC 11.2.0.2.

    Have several reports of an interactive report. According to the documents (and saved reports URL provided in developer mode Apex), the URL should display the specified saved report (e.g., f? p = 957:18: & APP_SESSION.: I R_REPORT_54417).

    The relevant report (e.g. 54417) in this example is a GROUP BY adding a measure ordering the report in cumulative value decreasing, giving a "Top N" report saved view.

    The URL call works the IR report displays the specified report. The drop-down list of REPORTS displays the title correct saved report. The display of the icon/text under the IR toolbar shows "report saved" as the Top N report.

    However, the GROUP BY is missing from that (which means the GROUP defined BY for this report recorded was not applied). And the GROUP BY is not displayed in the grid of IR data. The data in the grid is rather that of the standard (primary) State.

    Am I missing something about how saved IR reports work when called via a URL?

    The fact that demand IR_REPORT does not display the correctly selected saved report public, seems to be a bug.

    Workaround in case anyone experience this problem.

    Get the value of the report is saved in the select list (id apex_IR_SAVED_REPORTS). In my case:

    Pass a custom in the URL request (for example, TOP_N)-instead of IR_REPORT_.

    Add an HTML region (no model) which returns when v('REQUEST') = "TOP_N". Add the following Javascript call:

    Final result. Page is rendered as a public report by default. After, the gReport() of Javascript function is executed and simulates the user selects the saved report specified in the report list.

  • What does it mean to "reduce the selectivity"?

    Hello guys

    I try to understand the following

    As the columns are compressed from left to right, the columns must be ordered in decreasing selectivity to get the best compression.

    As far as I know, selectivity = number of distinct values / num lines

    So, if selectivity diminishes, the number distinct values decreases, right?

    Question 2: Correct me if I'm wrong, also a means of selectivity, if the sql query returns multiple rows, it is said that low selectivity. However, if the sql query returns multiple rows, it is said that strong selectivity.

    Thanks in advance.

    Talk you about the compression of the table or index of compression?  Or something else entirely?

    In the context of compression, if I read the line you quote, my interpretation of "lower selectivity" is "the column with the distinct values least is on the left, the column with the most distinct values concerning the right of it... and so on.

    Hemant K Collette

  • HA mode does not support more than one VC DC?

    OK, this is a minor blow of mouth/feature request...

    So according to what follows - http://kb.vmware.com/selfservice/microsites/search.do?language=en_US & cmd = displayKC & externalId = 2115878 #sf39023518

    vROps HA does not support separate nodes in DCs, it was a surprise for me, especially when the reason is latency again during a test on a 10 Gbps LAN it still does not work after a period of time(<2ms)

    Part of my hope/expectation (rightly or wrongly) was to cover 2 physical DCs (2xVCs) give me a solution truly HA when in fact the PA are now limited to be local HA (one could say that you can count on vSphere HA)

    Even in local mode HA doesn't protect you waste of time during the correction of the product... If its value decreases...

    Now, if I missed something please let me know I'd be happy to see different results from what I see above.

    Otherwise, consider this a feature request that vROps is really a great tool, but HA must be more that she should now be regarded as truly HA IMO.

    RV Ops HA is not intended or designed to manage data centers. Latency conditions are tight, stretching on domain controllers, it is impossible at this time (v6.0.2). HA mode is designed to protect your data/cluster falls down if you lose a single node of the cluster. The recommendation is to put the replica on host/different data store, so even if you leave the underlying resources for the master, you still have you cluster config/master role online. I support your hope that HA will get better, and I am sure that he will do!

Maybe you are looking for

  • How to print from an iPad Pro on a wired network printer?

    We have new iPads for our busines. They are Pros iPad on iOS 9.3.4. It would be a great help if we could get them to print on our WIRED network printer. The iPads are on LTE

  • iPad Air keeps crashing and restarting

    Why my iPad Air keep crashing and restarting in Safari? I also think other applications. iOS 9.3.2 must be the culprit because it never happened so often. Any solution?

  • What is my folder of the application that is supposed to look like?

    Im not sure of what was originally in my app folder. I would delete that I don't have here in it. Can someone help me? like the games in Trion who is supposed to be here? What is SyphonInject? What is log files? Help, please!

  • L20-120: need help for installing Windows XP

    I recently bought a laptop Toshiba L20-120 with the operating system of Windows XP in German but would like to install the English version. I need help on how to on this subject. I have Windows XP 2002 edition, is this compatible or that we should in

  • Two monitors operations does not not on HP Envy H8

    I have a similar (or perhaps the same) problem with two screens on a HP Envy H8 1437 with Win 8 capacities (64) installed on this system, however; I try to use two DVI ports on the system. I use two HP W2371b monitors. I can't really tell what is the