NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW1] FW-1 4.1 SP-3 problem: Licensed host count doubles after first po licy install following reboot



Title: FW-1 4.1 SP-3 problem: Licensed host count doubles after first policy install following reboot

Platform: IP330
OS: IPSO 3.3-FCS3
FW-1: 4.1 SP-3

Procedure:
fwstop; cd $FWDIR/database; rm fwd.h fwd.hosts; sync; sync; sync; reboot
Log in
Allow a few minutes to pass while FW-1 collects licensed hosts entries.
Load Policy Editor, install policy (with no changes) on the firewall.
While the policy is being compiled and installed, continuously do
"fw tab" in a shell.

Output from fw tab:

wall[admin]# fw tab -t host_table -s
HOST                  NAME                          ID  #VALS
localhost             host_table                  8185     34
wall[admin]# !!
fw tab -t host_table -s
HOST                  NAME                          ID  #VALS
localhost             host_table                  8185     35
wall[admin]# !!
fw tab -t host_table -s
HOST                  NAME                          ID  #VALS
localhost             host_table                  8185     43
wall[admin]# !!
fw tab -t host_table -s
HOST                  NAME                          ID  #VALS
localhost             host_table                  8185     44
wall[admin]# !!
fw tab -t host_table -s
HOST                  NAME                          ID  #VALS
localhost             host_table                  8185     45
wall[admin]# !!
fw tab -t host_table -s
HOST                  NAME                          ID  #VALS
localhost             host_table                  8185     90
wall[admin]# !!
fw tab -t host_table -s
HOST                  NAME                          ID  #VALS
localhost             host_table                  8185     90
wall[admin]#

What's going on?

By the way, why does "fw lichosts" take so long to run, even if I have /etc/hosts entries already populated for the IPs it's reporting?

Thanks,
-Anthony Garcia
[email protected]



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.