Ghost in the machines

BillRobinson

Member
Join Date
Oct 2006
Location
Sydney, Nova Scotia
Posts
185
See who can diagnose this one.

ControlLogix talking to a micro850 via ethernet (CIP table read/writes).
Logix is also talking to a compactlogix and FTVserver
Switch is a managed Ntron with IGMP with Query enabled
Cisco firewall/DHCP server also attached to network
All devices have static IP's (DHCP is for unconnected clients)

When firewall is connected messages to the micro850 initially work.
Messages work for about 30 minutes but then fail and do not recover
Error message 16#001f 16#0000_0204 Error processing connection related service

Pinging the Micro850 both before and after a failure lockup produces 1 valid response (1st ping) and the rest fails (timeout); a -t produces infinite timeouts. If a second ping command is made after the first set, it reacts the same way, 1st ping is good, the rest fail.

When firewall is removed pinging is normal and communication messages do not fail.

When firewall is connected all other devices communicate perfectly.

Any input at all would be helpful, I am at wits ends.
 
I suspect something in communications is triggering the firewall. It is protecting from a perceived attack. Maybe sending strange messages to the 850. Send error message to Cisco and AB. Cisco might have a software/flash update for the firewall, if they know what a micro 850 is.
 
Last edited:
If it works for a while then stops it seems more of a hardware issue than a software / firewall rule issue.

Can you use a different interface port on the firewall? Can you log into the firewall and do a packet capture? A packet capture will give you a better idea of where the problem is.
 
Cisco might be overzealous in their DDoS protection, perhaps. Could be a network utilization issue.

As suggested by The Plc Kid, a packet capture (Wireshark is awesome if you haven't used it) can certainly help diagnose this.
 
What model of Cisco firewall device are you using ?

Are all of the automation devices on the same side of the firewall ?

If traffic between the controllers is not passing *through* the firewall, I don't see how it could affect them.

It's possible that the Cisco device is doing some kind of device detection that is confusing the Micro 850.

I agree that Wireshark is the best tool for this. Mirror the Micro 850's port to an unused port on the switch, connect Wireshark, and see what's going on.
 
Some monitoring with WireShark would be great but I was primarily making reference to the internal packet capture tool built into the firewall.

This will detect traffic that is only inside the firewal like vlan routing ,ACL , Inboud /Outbound rules, Interface routing , etc.

@ the OP is this a new setup? Has it been working in the past with no issues? was something added,removed or changed?
 
SOLVED: Ended up being a firewall issue, (ARP issue I believe). The strange thing was that it only affected the micro850, the control logix, compact logix, FTV and a Panelview were unaffected. Thanks for the help folks!
 

Similar Topics

Guys I know this may not be a PLC question but I do have a issue that I was needing some advise. I was needing to know the best way to create a...
Replies
6
Views
1,958
I need to ghost this machine. ALLEN BRADLEY 1500P Cat 6181P-15A2MW71AC MAT N0 PN 337626 DIR: 10002125617/00 20FEB2017 Windows 7 Professional I...
Replies
1
Views
1,360
Can't take credit for this, a friend had seen it. But Rockwell, etc. were all lost. Relay output card. Large rack. LOTS of outputs. Output...
Replies
1
Views
1,471
Hi everyone, had an odd occurence happen and wondering if its ever happened to anyone else in their field. Programming a GE RX3I with...
Replies
7
Views
1,869
While creating a runtime, the progress window shows: compression Tag\ABC1_ABC.db.wat The ABC1_ABC is a project\target\tag\???? from a previous...
Replies
1
Views
1,576
Back
Top Bottom