SR520 Locks up with Domain traffic

Hello everyone, we are having an issue with a SR520 that I though I'd run by everyone.
We have a SR520 setup with a site to site VPN to an ASA5505. The SR520 has 10 computers behind it and the ASA has 15 computers behind it, including the domain controller. Everything has been running smooth without issue, traffic passing in both directions, etc. However, we recently installed a Windows Domain controller (SBS 2008) at the main (asa) site and would like to start joining computers at the remote (sr520) site to the domain. What we found out is that the domain traffic locks up the SR520. So, if none of the computers are joined to the domain, it runs fine, traffic can flow in both directions. We join a computer to the domain & after a couple hours we can't access the main site from the remote site. We can access the remote site from the main site. Also, the computers at the remote site can't access the internet, although we can ping the outside interface of the SR (from a remote host), and even ssh to the SR through the VPN which runs across the internet service. We reboot the SR520 and everything works fine, for a couple of hours.
I reviewed the access-lists and the traffic seems to be qualifying for the correct lists. I even tried to clear the acl counters, but no luck.
My best theory, at this point, is that the domain traffic exceeds some limit and the SR gets confused and can't route the traffic anymore.
At any rate, I had a few questions in regards to this:
1. Any ideas?
2. Could this be a problem with the domain traffic exceeding some compacity on the SR520? If so, how would I measure that?
3. Does anyone have any experience with a scenario like this? Specifically, with running a SR520 at a remote site with domain-joined computers?
4. Are there any specific debug commands that we can use to troubleshoot this?
I can upload the configs also, but I wanted to get the discussion going. We are trying to get the smartnet cleared up, so I can open a case with the TAC, but until then I just have to do my best.
Thanks,
Ben

1) LAN port speed doesn't appear to have any effect
2) Forcing a connection type doesn't seem to have any effect. This is also rather impractical.
3) I don't have that option (though there is a TKIP/AES mixed option). Either way, I'd rather not have to resort to using a weaker encryption method.
4) No effect.
I did manage to find some information about the error message (older versions of firmware didn't even offer that clue).
http://www.dd-wrt.com/wiki/index.php/Advanced_wireless_settings#Beacon_Interval
I ended up increasing the beacon interval from 100ms to 500ms under Wireless > Advanced Settings.
The wifi analyzer app on android seems to keep dropping the SSID when the beacon interval is set that high, so I might have to adjust it to find a good balance.
However, while it was set to 500ms, none of the access points went down for two days.
[edit]: I reduced the beacon interval incrementally down to 300ms. It started locking up at 250ms.

Similar Messages

  • Machine locks up with spinning colored ball while in finder

    Frequently, while doing searches through my photos with Finder and trying to copy a photo from one folder to another the system locks up with the spinning colored ball. How do I kill the action(on my PC it was Control Alt Delete).
    My system is MacBook Pro (Retina, 15-inch, Mid 2014 16 GB)

    4/16/15 9:29:20.870 AM sandboxd[422]: () QuickLookSatelli(852) deny file-issue-extension /Users/richardbost/Library/Caches/com.apple.quicklook.satellite
    4/16/15 9:29:20.875 AM QuickLookSatellite[852]: CGSConnectionByID: 0 is not a valid connection ID.
    4/16/15 9:29:20.875 AM QuickLookSatellite[852]: Invalid Connection ID 0
    4/16/15 9:29:20.894 AM sandboxd[422]: () QuickLookSatelli(852) deny mach-lookup com.apple.nsurlstorage-cache
    4/16/15 9:29:20.918 AM sandboxd[422]: () QuickLookSatelli(852) deny file-issue-extension /Users/richardbost/Library/Caches/com.apple.quicklook.satellite
    4/16/15 9:29:20.958 AM sandboxd[422]: () QuickLookSatelli(852) deny mach-lookup com.apple.nsurlstorage-cache
    4/16/15 9:32:48.410 AM com.apple.xpc.launchd[1]: (com.apple.imfoundation.IMRemoteURLConnectionAgent) The _DirtyJetsamMemoryLimit key is not available on this platform.
    4/16/15 9:33:19.830 AM WindowServer[141]: disable_update_timeout: UI updates were forcibly disabled by application "Finder" for over 1.00 seconds. Server has re-enabled them.
    4/16/15 9:33:33.372 AM WindowServer[141]: common_reenable_update: UI updates were finally reenabled by application "Finder" after 14.54 seconds (server forcibly re-enabled them after 1.00 seconds)
    4/16/15 9:33:50.244 AM WindowServer[141]: disable_update_timeout: UI updates were forcibly disabled by application "Finder" for over 1.00 seconds. Server has re-enabled them.
    4/16/15 9:33:56.847 AM WindowServer[141]: common_reenable_update: UI updates were finally reenabled by application "Finder" after 7.60 seconds (server forcibly re-enabled them after 1.00 seconds)
    4/16/15 9:39:07.867 AM storeaccountd[330]: AccountServiceDelegate: Accepting new connection <NSXPCConnection: 0x7fb970c28a60> connection from pid 365 with interface <AccountServiceInterface: 0x7fb970c024b0> (PID 365)
    4/16/15 9:39:14.716 AM identityservicesd[272]: ====== IDS Traffic Usage:
    4/16/15 9:39:14.716 AM identityservicesd[272]:     Service: com.apple.madrid
    4/16/15 9:39:14.716 AM identityservicesd[272]:       query-requests: 1
    4/16/15 9:39:14.716 AM identityservicesd[272]:
    4/16/15 9:39:14.716 AM identityservicesd[272]:     Service: com.apple.ess
    4/16/15 9:39:14.716 AM identityservicesd[272]:       query-requests: 1
    4/16/15 9:39:14.716 AM identityservicesd[272]:
    4/16/15 9:39:14.716 AM identityservicesd[272]: ====== Done
    4/16/15 9:43:02.539 AM WindowServer[141]: disable_update_timeout: UI updates were forcibly disabled by application "Finder" for over 1.00 seconds. Server has re-enabled them.
    4/16/15 9:43:16.540 AM WindowServer[141]: disable_update_likely_unbalanced: UI updates still disabled by application "Finder" after 15.00 seconds (server forcibly re-enabled them after 1.00 seconds). Likely an unbalanced disableUpdate call.
    4/16/15 9:43:47.331 AM WindowServer[141]: common_reenable_update: UI updates were finally reenabled by application "Finder" after 45.79 seconds (server forcibly re-enabled them after 1.00 seconds)
    4/16/15 9:43:47.337 AM Finder[245]: void CGSUpdateManager::log() const: conn 0xff0b: spurious update.
    4/16/15 9:43:53.480 AM WindowServer[141]: disable_update_timeout: UI updates were forcibly disabled by application "Finder" for over 1.00 seconds. Server has re-enabled them.
    4/16/15 9:44:07.480 AM WindowServer[141]: disable_update_likely_unbalanced: UI updates still disabled by application "Finder" after 15.00 seconds (server forcibly re-enabled them after 1.00 seconds). Likely an unbalanced disableUpdate call.
    4/16/15 9:44:11.000 AM kernel[0]: process Finder[245] thread 2577 caught burning CPU! It used more than 50% CPU (Actual recent usage: 53%) over 180 seconds. thread lifetime cpu usage 202.831385 seconds, (195.815528 user, 7.015857 system) ledger info: balance: 90007893139 credit: 202687364411 debit: 112679471272 limit: 90000000000 (50%) period: 180000000000 time since last refill (ns): 168662847166
    4/16/15 9:44:11.557 AM com.apple.xpc.launchd[1]: (com.apple.ReportCrash[864]) Endpoint has been activated through legacy launch(3) APIs. Please switch to XPC or bootstrap_check_in(): com.apple.ReportCrash
    4/16/15 9:44:11.558 AM ReportCrash[864]: Invoking spindump for pid=245 thread=2577 percent_cpu=53 duration=170 because of excessive cpu utilization
    4/16/15 9:44:11.996 AM spindump[428]: Saved cpu_resource.diag report for Finder version 10.10.4 (10.10.4) to /Library/Logs/DiagnosticReports/Finder_2015-04-16-094411_Richards-MacBook-Pro.c pu_resource.diag
    4/16/15 9:44:58.297 AM WindowServer[141]: common_reenable_update: UI updates were finally reenabled by application "Finder" after 65.82 seconds (server forcibly re-enabled them after 1.00 seconds)
    4/16/15 9:47:30.693 AM com.apple.xpc.launchd[1]: (com.apple.imfoundation.IMRemoteURLConnectionAgent) The _DirtyJetsamMemoryLimit key is not available on this platform.
    4/16/15 9:47:30.965 AM com.apple.iCloudHelper[868]: objc[868]: Class FALogging is implemented in both /System/Library/PrivateFrameworks/FamilyCircle.framework/Versions/A/FamilyCircl e and /System/Library/PrivateFrameworks/FamilyNotification.framework/Versions/A/Famil yNotification. One of the two will be used. Which one is undefined.
    4/16/15 9:47:30.995 AM com.apple.xpc.launchd[1]: (com.apple.imfoundation.IMRemoteURLConnectionAgent) The _DirtyJetsamMemoryLimit key is not available on this platform.
    4/16/15 9:47:31.297 AM com.apple.xpc.launchd[1]: (com.apple.imfoundation.IMRemoteURLConnectionAgent) The _DirtyJetsamMemoryLimit key is not available on this platform.
    4/16/15 9:48:38.276 AM WindowServer[141]: _CGXSetWindowHasKeyAppearance: Operation on a window 0x2c requiring rights kCGSWindowRightOwner by caller Dashboard
    4/16/15 9:48:38.279 AM WindowServer[141]: _CGXSetWindowHasMainAppearance: Operation on a window 0x2c requiring rights kCGSWindowRightOwner by caller Dashboard
    4/16/15 9:50:12.422 AM pkd[270]: enabling pid=303 for plug-in com.apple.ncplugin.stocks(1.0) 20DD9C99-57EC-42CD-8430-700AD6FC9DA0 /System/Library/Frameworks/NotificationCenter.framework/PlugIns/com.apple.ncplu gin.stocks.appex
    4/16/15 9:50:12.423 AM locationd[80]: Couldn't find a requirement string for masquerading client /System/Library/Frameworks/NotificationCenter.framework/PlugIns/com.apple.ncplu gin.weather.appex
    4/16/15 9:50:12.423 AM locationd[80]: could not get apple languages array, assuming english
    4/16/15 9:50:12.423 AM pkd[270]: enabling pid=303 for plug-in com.apple.ncplugin.weather(1.0) B2A83AE6-90A7-4EE1-99A2-2B95BDCB36A6 /System/Library/Frameworks/NotificationCenter.framework/PlugIns/com.apple.ncplu gin.weather.appex
    4/16/15 9:50:12.424 AM pkd[270]: enabling pid=303 for plug-in com.apple.iCal.CalendarNC(1.0) 2B9E7662-5BEA-4F82-AAD3-C677802923A3 /Applications/Calendar.app/Contents/PlugIns/com.apple.iCal.CalendarNC.appex
    4/16/15 9:50:12.449 AM com.apple.xpc.launchd[1]: (com.apple.imfoundation.IMRemoteURLConnectionAgent) The _DirtyJetsamMemoryLimit key is not available on this platform.
    4/16/15 9:50:12.535 AM locationd[80]: Location icon should now be in state 'Active'
    4/16/15 9:50:12.577 AM com.apple.xpc.launchd[1]: (com.apple.imfoundation.IMRemoteURLConnectionAgent) The _DirtyJetsamMemoryLimit key is not available on this platform.
    4/16/15 9:50:12.647 AM locationd[80]: Couldn't find a requirement string for masquerading client /System/Library/Frameworks/NotificationCenter.framework/PlugIns/com.apple.ncplu gin.weather.appex
    4/16/15 9:50:12.648 AM locationd[80]: could not get apple languages array, assuming english
    4/16/15 9:50:12.722 AM networkd[170]: -[NETClientConnection scrubParametersForEntitlements:] client com.apple.ncplu.875 setting source application without entitlement
    4/16/15 9:50:13.336 AM networkd[170]: -[NETClientConnection scrubParametersForEntitlements:] client com.apple.ncplu.875 setting source application without entitlement
    4/16/15 9:50:13.336 AM networkd[170]: -[NETClientConnection scrubParametersForEntitlements:] client com.apple.ncplu.875 setting source application without entitlement

  • Yoga 2 Pro - Veriface doesnt work with Domain Account

    I have a Yoga 2 Pro and I can get Veirface to work fine with a local account but it will not work with a Domain Account. I can get it to where it prompts me for the Domain Account Password (as it should the 1st time) but when you enetr the proper password, it tells you ints invalid etc. I have tried changing the Domain Password but it acts like it just cant locate the account etc. Does anyone know if this is a known issue or if there is a resolution to this?
    I am using Veriface 5.0.13.5261 on a Windows 8.1 Pro Operating System

    Hi there, i had the same problem.
    I have two accounts
    1. valentia\mubi (which is domain account)
    2. Mubi (which is local laptop account)
    When i use register my account with veriface, it work fine with Mubi
    When i use to register my account with valentia\mubi it say wrong password..
    I even deleted local i.e. Mubi account but still no luck!
    This is great feature, but pretty much useless if not working with domain. I have to use domain account, 

  • My ipad is locked up with the screen showing the usb port connecting to itunes.  I had not synched by ipad to my computer in a long time so yesterday it was downloading software upgrades for 5 hours.  then the screen was locked up.

    My ipad is locked up with the screen showing  a picture of the usb port with an arrow to itunes.

    Then connect your iPad to your computer and use iTunes to restore. 

  • I have a iPhone 4 and lately it has been shutting down randomly when I still have battery left. It also doesn't turn back on, until I plug it in to the charger. But when I plug it in, the low battery sign shows up then comes to the lock screen with 68%.

    I have a iPhone 4 and lately it has been shutting down randomly when I still have battery left. It also doesn't turn back on, until I plug it in to the charger. But when I plug it in, the low battery sign shows up then comes to the lock screen with like 68% left.

    Morning Clementine Lin,
    For more information this, please see this article:
    iPhone: Hardware troubleshooting
    http://support.apple.com/kb/ts2802
    Take a look at the Will not turn on, will not turn on unless connected to power, or unexpected power off section.
    Have a nice day,
    Mario

  • HT201412 did a software update and now the only thing I get is the itunes logo and arrow pointing up and a lock symbol with a line going down toward the screen button.  Any suggestions to get this to open?

    Trying to get the ipad to open after doing a software update.  I only get the itunes logo with an arrow pointing toward it and a lock symbol with a line going down towards the screen button.  Any suggestions to get this to open?

    You are in Recovery Mode. Follow the instructions below to recover your iPad.
    http://support.apple.com/kb/ht4097

  • Windows Server 2008 R2: Server unable to authenticate with Domain Controller

    Hello, I was wondering what could be the reason for this error if it is certain that there was no other computer on the network using the same name:
    This computer could not authenticate with<Domain-controller>, a Windows domain controller for domain <Domain-name>, and therefore this computer might deny logon requests. This
    inability to authenticate might be caused by another computer on the same network using the same name or the password for this computer account is not recognized. 
    What would cause the machine account pw to be 'not recognized'?

    You can track changes in AD by enabling AD Auditing: https://technet.microsoft.com/en-us/library/cc731764%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396
    As reading the logs is usually a complicated and time consuming task, it is recommended to use a third party tool for auditing. The one I usually recommend is Lepide Auditor - Active Directory: http://www.lepide.com/lepideauditor/active-directory.html
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • We have a corporate iPad in our auto showroom to show guests how to use features on their vehicles. Someone locked it with their account. It was not an employee. How can I get in? I did a restore of the software already?

    We have a corporate iPad in our auto showroom to show guests how to use features on their vehicles. Someone locked it with their account. It was not an employee. How can I get in? I did a restore of the software already?

    Gather up the proof that the dealership is the original purchaser of the iPad,
    and take the iPad & that proof to a physical Apple store for possible assistance.
    It is highly suggested that you make a genius bar appointment to avoid delay
    at the store:
    Make a Genius Bar Reservation
    http://www.apple.com/retail/geniusbar/
    If no Apple store close by, get the information mentioned above and contact
    Apple Contact Us for assistance.
    Once the problem is resolved, you may wish it use Guided Access to limit
    what customers can do with the iPad.
         iOS: About Guided Access - Apple Support

  • I am able to see my ipod touch 5th geneneratio in find my iphone on icloud but it is showing offline.... i think its stolen but i have locked it with a passcode and the person who i suspect doesnt know it... i wana get it back what should i do??

    i am able to see my ipod touch 5th geneneration in find my iphone on icloud but it is showing offline.... i think its stolen but i have locked it with a passcode and the person who i suspect doesnt know it... i wana get it back what should i do??

    lost/stolen                                     
    No app on the iPod is required.                           
    - If you previously turned on FIndMyiPod on the iPod in Settings>iCloud and wifi is on and connected, on a computer browser go to iCloud: Find My iPhone, sign in and go to FIndMyiPhone. If the iPod has been restored it will never show up or conbtinue to show off-line.
    - You can also wipe/erase the iPod and have the iPod play a sound via iCloud.
    iCloud: Erase your device
    iCloud: Use Lost Mode
    - If not shown/shown off, then you will have to use the old fashioned way, like if you lost a wallet or purse.
    - Change the passwords for all accounts used on the iPod and report to police
    - There is no way to prevent someone from restoring the iPod (it erases it) using it unless you had iOS 7 on the device. With iOS 7, one has to enter the Apple ID and password to restore the device.
    - Apple will do nothing without a court order                                               
    Reporting a lost or stolen Apple product                                              
    - iOS: How to find the serial number, IMEI, MEID, CDN, and ICCID number

  • While transferring several files to the G-Raid, the G-Raid device locks up with the following warnings:   "The Finder can't complete the operation because some data in (whatever file) can't be read or written (Error code - 36)."

    While transferring several files to the G-Raid, the G-Raid device locks up with the following warnings:   "The Finder can't complete the operation because some data in (whatever file) can't be read or written (Error code - 36).” NOt sure this is a G-Raid problem, can anyone help?

    This is likely a problem with the drive itself. This error indicates unspecified I/O errors with the drive, which can be from a hardware fault, or a formatting issue. If the drive has valuable data on it, then try connecting it to another PC to get the data off, and then try fully partitioning and formatting the drive with Disk Utility. If this corrects the error then you should be able to use the drive again as it was likely a formatting issue, but if the problem continues then it is likely a hardware fault and the best solution is to be safe and replace the drive.

  • I am feeling so ripped off right now. I have wanted a Mac for years and believed the hype about it's stability and I have had more trouble with this Imac 2011 than I have ever had with a pc. It locks up with several software products from APP store.

    I am feeling so ripped off right now. I have wanted a Mac for years and believed the hype about it's stability and I have had more trouble with this Imac 2011 than I have ever had with a pc. It locks up with several software products from APP store. I have already had to have a technician to look at it and really couldn't figure out what the deal was.  I was told that the APP store software should give me no problems but the truth is that it locks up on the software. This machine is only 4 weeks old and I am using 37 g on a 1 T hard drive. There is no reason for it to be locking up. Also, when I try to use the help program, it always tells me that I am not connected to the internet even though I have used both the mail program and the browser with no problem just before that. I successfully used the help program on my pc lots of times. I did not need a $2000. plus machine to just get email. I just wanted to unload on somebody that might understand my pain and after checking out this site...I think there is a few of you out there.

    I was told that the APP store software should give me no problems but the truth is that it locks up on the software.
    The apps downloaded from the Mac App Store are written by third party developers, not Apple. If you have problems  with those apps you need to visit the support area for their websites. Launch the App Store, locate the app name. You should see a support link.
    when I try to use the help program, it always tells me that I am not connected to the internet even though I have used both the mail program and the browser with no problem just before that
    Go to ~/Library/Preferences. Move the com.apple.helpviewer.plist file from the Preferences folder to the Trash. Restart your Mac, try the Help menu.
    If you need help finding that file, hold down the Finder icon in the Dock then click: New Finder Window. From the menu bar top of your screen click: Go > Go to Folder. Type this in exactly as you see it here:   ~/Library/Preferences/com.apple.helpviewer.plist    That will take you right to that file.
    (.plist) files stores information about a particular app or in this case, the Help viewer. Often times deleting the .plist file resolves the issue.
    It's fine to "unload"... we understand that you expect your iMac to be stable but there are times when things go awry. That's why we have these forums so that you can you get help.
    You may want to read up on how to repair the disk if necessary or reintsall Lion >  OS X Lion: About Lion Recovery
    Apple - Find Out How - Mac Basics
    How to "switch" from PC to Mac >  Apple - Support - Switch 101
    I'm sorry you feel, "ripped off", but you are using the world's most advanced operating system and it may take some time to adjust to a new OS.   http://developer.apple.com/technologies/mac/

  • My older ibook g4 is locked up with an icon flashing. looks like a file folder flashing a blue and white face/question mark. what is this?

    my older ibook g4 is locked up with an icon flashing. looks like a file folder flashing a blue and white face/question mark. what is this?

    Apple's suggestions for dealing with the flashing question mark folder:
    http://support.apple.com/kb/TS1440?viewlocale=en_US
    Niel has summed it up pretty nicely.

  • Is it possible to enter the lock screen with itunes or something else because i've damaged my phone and the touch screen is damaged that i'm not able to unlock it to make a backup on itunes

    is it possible to enter the lock screen with itunes or something else because i've damaged my phone and the touch screen is damaged that i'm not able to unlock it to make a backup on itunes ?
    it would be very important to put the data from iphone 5 to my new 5s ..
    looking forward to get some help
    thx

    You cant unlock your phone unless you put in your password. It may be possible that the apple store could do something about it.

  • I downloaded new version of itunes. Then itunes asked if i wanted the latest version for ipod. itunes said it was getting ipod ready for download, then there was an error message. Now ipod is locked up with a apple on the screen and a line under it

    I downloaded the latest version of itunes. Then itunes asked if i wanted the latest version on ipod. Itunes was getting ipod ready then a error happened. Now ipod is locked up with a apple on screen with a download line under it. Also itunes will not recognize ipod like it has before. If anyone can help it would be appreciated. Thanks

    Do a hard reset, put it in DFU Mode and do a manual install, as outlined in the link below.
    Basic troubleshooting steps  
    17" 2.2GHz i7 Quad-Core MacBook Pro  8G RAM  750G HD + OCZ Vertex 3 SSD Boot HD 
    Got problems with your Apple iDevice-like iPhone, iPad or iPod touch? Try Troubleshooting 101
     In Memory of Steve Jobs 

  • Get the pc name with domain name and add it to my properties file using commands

    i want to get the pc name with domain name and add it to my properties file using powershell  .
    sid

    function Get-Environment{
    [environment]|Get-Member -Static -MemberType Properties |
    ForEach-Object{
    if($_.Name -ne 'StackTrace'){
    $v=[scriptblock]::Create("[environment]::$($_.Name)").Invoke()
    New-Object PsCustomObject -Property ([ordered]@{Name=$_.Name;Value=$v[0]})
    Get-Environment
    Get-Environment | Out-String | Out-File environment.txt
    ¯\_(ツ)_/¯

Maybe you are looking for

  • Error installing Adobe Premiere Pro 2.0 on winows 7

    Installing Adobe Premiere Pro 2.0 on my new Winows 7 computer and get an error 1311.source file not found.  The last file shown on the addy is Data1.cab.  Does anybody have an idea why that program will not install?  Thanks........

  • ORA-00600: internal error code, arguments: [25012], [954], [0], []

    I got ORA-00600: internal error code, arguments: [25012], [954], [0], [] while doing bulk insert and bulk collect.I am in contact with oracle support.In the mean can you give your views about this error.What might caused to this error.What things nee

  • Converting Word (2003) to PDF?

    I need to convert a Word file (2003) to PDF.  How do I do this? I have both Reader and Acrobat on my computer.  I tried Acrobat but it downloaded the file as another Word file not the PDF I need.  Thanks. Steven Oregon

  • In-ear headphones buzzing

    I got some new in-ear headphones a little bit ago. The right ear has this buzzing/crackling sound. Is there any way to fix it or get a replacement pair?

  • About AT SELECTION SCREEN

    Hi guys, I need help about AT SELECTION SCREEN ON VALUE REQUEST FOR a. Actually, I need this to be ON VALUE REQUEST FOR a and b, because I need to update both parameter with this single search help. Can anybody show me how to do this? Thanks before.