<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Redirecting CWS Traffic To Inside Interface in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/asa-redirecting-cws-traffic-to-inside-interface/m-p/3333855#M538</link>
    <description>&lt;P&gt;We are seeing a very strange issue with CWS on our ASA recently.&amp;nbsp; Users report that all HTTPS traffic is failing.&amp;nbsp; We disable the service rule sending that traffic to CWS and functionality is restored.&amp;nbsp; A set of test users on a separate service rule continue to work.&amp;nbsp; HTTP traffic on it's own rule continues to work.&amp;nbsp; At some point later the service rule is re-enabled and traffic goes to CWS as expected and works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This morning I noticed something strange on the syslogs from the ASA.&amp;nbsp; During the problem time I see syslog entries saying that traffic from the outside on a given connection is being redirected to the CWS tower on the inside interface.&amp;nbsp; In one minute of the problem time I saw 13,350 of these messages.&amp;nbsp; The connection number mention in the message is a connection that was started on the inside and I can see the syslog event stating that it was redirected to the CWS tower on the outside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So it seems to me that the return traffic should not be redirected at all, let alone pointed at the inside interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We recently upgraded the ASA to 9.8(2).20 but it was more than a week before we started seeing this problem.&amp;nbsp; Now that I know what to look for I can see that we get a handful of these events every day but very sporadically.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone seen anything like this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Sat, 09 Mar 2019 01:42:02 GMT</pubDate>
    <dc:creator>dethomas</dc:creator>
    <dc:date>2019-03-09T01:42:02Z</dc:date>
    <item>
      <title>ASA Redirecting CWS Traffic To Inside Interface</title>
      <link>https://community.cisco.com/t5/cloud-security/asa-redirecting-cws-traffic-to-inside-interface/m-p/3333855#M538</link>
      <description>&lt;P&gt;We are seeing a very strange issue with CWS on our ASA recently.&amp;nbsp; Users report that all HTTPS traffic is failing.&amp;nbsp; We disable the service rule sending that traffic to CWS and functionality is restored.&amp;nbsp; A set of test users on a separate service rule continue to work.&amp;nbsp; HTTP traffic on it's own rule continues to work.&amp;nbsp; At some point later the service rule is re-enabled and traffic goes to CWS as expected and works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This morning I noticed something strange on the syslogs from the ASA.&amp;nbsp; During the problem time I see syslog entries saying that traffic from the outside on a given connection is being redirected to the CWS tower on the inside interface.&amp;nbsp; In one minute of the problem time I saw 13,350 of these messages.&amp;nbsp; The connection number mention in the message is a connection that was started on the inside and I can see the syslog event stating that it was redirected to the CWS tower on the outside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So it seems to me that the return traffic should not be redirected at all, let alone pointed at the inside interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We recently upgraded the ASA to 9.8(2).20 but it was more than a week before we started seeing this problem.&amp;nbsp; Now that I know what to look for I can see that we get a handful of these events every day but very sporadically.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone seen anything like this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/asa-redirecting-cws-traffic-to-inside-interface/m-p/3333855#M538</guid>
      <dc:creator>dethomas</dc:creator>
      <dc:date>2019-03-09T01:42:02Z</dc:date>
    </item>
  </channel>
</rss>

