{"id":727,"date":"2011-07-01T18:57:10","date_gmt":"2011-07-01T17:57:10","guid":{"rendered":"http:\/\/blogs.oucs.ox.ac.uk\/networks\/?p=727"},"modified":"2011-07-05T10:15:58","modified_gmt":"2011-07-05T09:15:58","slug":"firewall-firefighting","status":"publish","type":"post","link":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/2011\/07\/01\/firewall-firefighting\/","title":{"rendered":"Firewall firefighting"},"content":{"rendered":"<p>The intention of this post is to explain what&#8217;s been happening with the University Firewall, what we&#8217;ve been doing about it and what we intend to do.<\/p>\n<p>The University Firewall Service is provided by a pair of Cisco FWSMs running as an active\/standby failover pair in a Cisco Catalyst 6500 chassis.<\/p>\n<p>Over the past month or so there have been a couple of fifteen-minute interruptions to the University&#8217;s Internet connection.\u00a0 Our investigations suggested that the FWSMs may have been to blame.\u00a0 We contacted the Cisco TAC (Technical Assistance Centre) for a comprehensive diagnosis but since we were running an old version of the FWSM firmware, they wanted us to upgrade to the latest version before helping us.\u00a0 This firmware upgrade was scheduled for early on the morning of Tuesday 28th June.<\/p>\n<p>During the evening of Monday 27th the active FWSM entered a state of continually rebooting.\u00a0 The standby FWSM did not takeover which resulted in the University being cut off from the Internet.\u00a0 Networks staff came in to the office on a voluntary basis and applied an emergency workaround.\u00a0 This consisted of bypassing the firewalls completely and recreating the ruleset as an ACL (Access Control List).\u00a0 An ACL doesn&#8217;t provide connection tracking like a firewall does but since the firewall policy is default open an ACL offers very similar functionality in our case.<\/p>\n<p>On Tuesday morning the FWSMs were upgraded as planned, put back into service, and the ACL removed.<\/p>\n<p>On Wednesday afternoon in an unrelated incident an IOS bug was triggered which led to a number of backbone Catalyst 6500s rebooting which resulted in the loss of network connectivity for ten minutes.\u00a0 The trigger for this bug is now known and we have put measures in place to prevent a repeat.\u00a0 The reboot of the FWSMs&#8217; 6500 caused them to fallover (which they shouldn&#8217;t) so we put the ACL back in service.<\/p>\n<p>Now that our FWSMs are running the latest software we have once again sought help from the Cisco TAC.\u00a0 The FWSMs are giving indications that they are not coping with our traffic load even though it is significantly lower than Cisco&#8217;s specification.\u00a0 On the basis that the FWSMs are suffering from a hardware fault, Cisco is sending us a pair of new FWSMs which we hope will arrive early next Monday.\u00a0 Assuming that they do arrive in time, we&#8217;ll prepare them on Monday and then put them into service during the standard maintenance window on Tuesday 5th July.<\/p>\n<p>EDIT 4th July: the replacement hardware arrived right at the end of the day so no swap-outs tomorrow morning.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The intention of this post is to explain what&#8217;s been happening with the University Firewall, what we&#8217;ve been doing about it and what we intend to do. The University Firewall Service is provided by a pair of Cisco FWSMs running &hellip; <a href=\"https:\/\/blogs-new.it.ox.ac.uk\/networks\/2011\/07\/01\/firewall-firefighting\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[123],"tags":[],"class_list":["post-727","post","type-post","status-publish","format-standard","hentry","category-firewall"],"_links":{"self":[{"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/posts\/727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/comments?post=727"}],"version-history":[{"count":5,"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/posts\/727\/revisions"}],"predecessor-version":[{"id":730,"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/posts\/727\/revisions\/730"}],"wp:attachment":[{"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/media?parent=727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/categories?post=727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs-new.it.ox.ac.uk\/networks\/wp-json\/wp\/v2\/tags?post=727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}