republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » pix and fragment riddle
Search Topic:
Uniqs:
150
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Ciscoworks »
« [Config] DynDNS.org on Cisco 871  
AuthorAll Replies

highland8

join:2005-05-24
POLAND

pix and fragment riddle

Hello

On CCSP i have question:
pixfirewall# show fragment
Interface: outside
Size: 200, Chain: 24, Timeout: 5, Threshold: 133

How may fragment packets have entered the outside interface of the PIX Security Appliance since the last time the clear fragment command was executed ?
There are several answers: 133,200,900,915,920,935
And 935 is correct. Why ??

snarohyans

join:2005-11-10
Indianapolis, IN

It looks to me like there is a portion missing to that question...

Typically when executing that command, you should get the following:

pixfirewall(config)# show fragment outside
Interface: outside
Size:2000, Chain:45, Timeout:10
Queue:1060, Assemble:809, Fail:0, Overflow:0

Which indicates:

•A database size limit of 2000 packets.
•The chain length limit of 45 fragments.
•A timeout of ten seconds.
•1060 packets currently awaiting re-assembly.
•809 packets have been fully reassembled.
•No failure.
•No overflow.

Therefore, to answer the question, you would add up the queue and assembled tallies to come up with a total of the number of fragmented packets that have entered the interface.

It sounds incomplete to me, but I might be missing something

Hope this helps!
Aaron
Forums » Equipment Support » Hardware By Brand » CiscoCiscoworks »
« [Config] DynDNS.org on Cisco 871  


Monday, 09-Nov 14:31:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [51] VoIP Over 3G Still Not Working For iPhone
· [23] Bill Would Force ISPs To Block Financial Scams
· [13] Verizon Keeps Swinging At AT&T
· [12] Mediacom Hints At 50, 100 Mbps Speeds
· [10] Clearwire To Get Another $1.5 Billion
· [6] 15 States Have Now Gotten Broadband Mapping Money
Most people now reading
· Divorce advice... [General Questions]
· [WIN7] Which Services in Win 7 Have You Turned Off? [Microsoft Help]
· Framed for child porn 151; by a PC virus [Security]
· My cat is reluctant to exercise. [General Questions]
· Blown out Ballasts [Home Repair & Improvement]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Bell disconnection fee? WTF? [TekSavvy]
· 60 Minutes piece on cyber security last night [Security]
· Your ideal heroic 5-man class comp! [World of Warcraft]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]