<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with FWSM and SQL*Net in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664433#M1028321</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to say that after a certain amount of time the FWSM tears down the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for my English.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Jan 2007 10:59:23 GMT</pubDate>
    <dc:creator>agustinmar</dc:creator>
    <dc:date>2007-01-22T10:59:23Z</dc:date>
    <item>
      <title>Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664430#M1028318</link>
      <description>&lt;P&gt;Hello, I have a FWSM and I have problem with Oracle server. The FWSM throws down the connections with Oracle server (port 1521). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw something message with this problem, but I haven't clear the solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please, someone can help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for my bad english.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664430#M1028318</guid>
      <dc:creator>agustinmar</dc:creator>
      <dc:date>2019-03-11T09:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664431#M1028319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marquez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly provide more details related to your setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible provide us the configuration( excluding sensitive details like public ip etc) along with the details of the involved components in this setup( oracle server ip, client ip etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have carried out some troubleshooting, kindly provide the details regarding the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-VJ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 10:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664431#M1028319</guid>
      <dc:creator>vijayasankar</dc:creator>
      <dc:date>2007-01-22T10:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664432#M1028320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say throws down the connections do you mean that the traffic is not allowed through or that it is but then after a certain amount of time the FWSM tears down the connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 10:54:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664432#M1028320</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-22T10:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664433#M1028321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to say that after a certain amount of time the FWSM tears down the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for my English.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 10:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664433#M1028321</guid>
      <dc:creator>agustinmar</dc:creator>
      <dc:date>2007-01-22T10:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664434#M1028322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are these connections from clients or from mid-tier servers. &lt;/P&gt;&lt;P&gt;We have faced a similiar problem on our pix firewalls, both standalone and FWSM. The mid-tiers would open database connections and then assume that these connection would be open forever. The firewall would tear them down if their was no activity on the connection but the mid-tier still assumed it was open so it didn't try to recreate a new connection. &lt;/P&gt;&lt;P&gt;We had to increase the tcp timeouts on our firewalls, on at least some of them we had to have an unlimited timeout, not ideal but they are coping okay. &lt;/P&gt;&lt;P&gt;The problem is that timeouts are global altho i believe with v3.1 you could apply a timeout to particular connections only without having to apply it to all connections through the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 11:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664434#M1028322</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-22T11:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664435#M1028323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marquez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with the post by the fellow netpro.&lt;/P&gt;&lt;P&gt;You might have to increase the TCP IDLE connection timetout values, so that the FWSM doesn't tears down a idle connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can tune the TCP connection timeout parameter as mentioned in the below URL&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_chapter09186a0080577c66.html#wp1058493" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_chapter09186a0080577c66.html#wp1058493&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-VJ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 11:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664435#M1028323</guid>
      <dc:creator>vijayasankar</dc:creator>
      <dc:date>2007-01-22T11:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664436#M1028324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For PIX/ASA, Optionally we can use the DCD feature available version 7.2 onwards.&lt;/P&gt;&lt;P&gt;Here's the URL to refer..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a008063705c.html#wp1053110" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a008063705c.html#wp1053110&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;-VJ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 12:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664436#M1028324</guid>
      <dc:creator>vijayasankar</dc:creator>
      <dc:date>2007-01-22T12:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664437#M1028325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi VJ &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for that. Very useful info. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 12:46:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664437#M1028325</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-22T12:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664438#M1028326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please, someone can send to me the config of some equipment of your with respect to timeouts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 13:16:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664438#M1028326</guid>
      <dc:creator>agustinmar</dc:creator>
      <dc:date>2007-01-22T13:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664439#M1028327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, I send the config of FWSM. I hope that you can help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 15:01:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664439#M1028327</guid>
      <dc:creator>agustinmar</dc:creator>
      <dc:date>2007-01-22T15:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664440#M1028328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marquez,&lt;/P&gt;&lt;P&gt;As mentioned in the URL provided by me in the earlier post, this would be the configuration to set the tcp timeout to 1440 minutes =&amp;gt; 24 hours. Change the value suitably to your requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname (config)#policy map tcp_conn_timeout&lt;/P&gt;&lt;P&gt;hostname (config)#class alltcp_traffic&lt;/P&gt;&lt;P&gt;hostname (config)#set connection timeout tcp 1440&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname (config)#service policy tcp_conn_timeout global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Kindly rate the post if it was helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-VJ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 15:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664440#M1028328</guid>
      <dc:creator>vijayasankar</dc:creator>
      <dc:date>2007-01-22T15:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664441#M1028329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, these connections are from mid-tier servers. Do you know how have I to change the timeouts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have posted the config too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you for all and sorry for my bad English.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 15:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664441#M1028329</guid>
      <dc:creator>agustinmar</dc:creator>
      <dc:date>2007-01-22T15:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664442#M1028330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello vijayasankar, I would to like to know if these commands need to be introduced in FWSM or in Catalyst 6500 where FWSM is installed. I comment this, because I have intended to introduce these commands in FWSM and FWSM don't support these commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 17:26:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664442#M1028330</guid>
      <dc:creator>agustinmar</dc:creator>
      <dc:date>2007-01-23T17:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664443#M1028331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marquez &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The commands VJ sent are for Firewall version 3.1. They are meant to be added to the FWSM not the MSFC. &lt;/P&gt;&lt;P&gt;Unfortunately you are running v2.3(3) and these commands are not supported in that release. &lt;/P&gt;&lt;P&gt;You can either upgrade, but be aware that 2.3 is equivalent to 6.3 pix and 3.1 is equivalent to version 7 so there are some major changes or &lt;/P&gt;&lt;P&gt;you can increase the timeout of ALL your tcp connections. In v2.3 it is a global setting so it will affect all tcp connections. &lt;/P&gt;&lt;P&gt;As i say we did this on some of our firewalls, not internet facing firewalls but firewalls in our data centre. &lt;/P&gt;&lt;P&gt;If you want to do this you need to change the timeout line ie from your config &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout conn 1:00 is for the tcp connections. 1:00:00 = 1 hour. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 17:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664443#M1028331</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-23T17:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664444#M1028332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marquez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had similar a issue with our backup software. TCP connection would remian open for too long and the FWSM would eventually terminate then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I change the timeout value to 8 hours and the problem was fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command on our FWSM running v2.3 was: timeout conn 8:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do this, keep an eye on your FW resources (memory) to make sure the number of open connections does exhaust you system (not likely unless you have a great number of connections)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2007 01:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664444#M1028332</guid>
      <dc:creator>fauresr</dc:creator>
      <dc:date>2007-01-25T01:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664445#M1028333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm experiencing similar issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an FWSM which originally run version 2.3(3). It is configured in multiple context mode. One of the contexts passes SQL*Net traffic (TCP port 1521).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recently I upgraded the FWSM to 3.1(8). The end-user started to complain that their backup application (using SQL) took 12 hours to complete compared to 2 hours previously before the FWSM upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Comparing the "timeout" commands of both 2.3 and 3.1, I notice they are the same, as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM 2.3(3)&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM 3.1(8)&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the following application inspection configs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map class_sip_tcp&lt;/P&gt;&lt;P&gt; match port tcp eq sip&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!             &lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512 &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect smtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt; class class_sip_tcp&lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;!        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The client is located at other parts of the network. The SQL server is located behind this FWSM context. Capturing packet trace on the client VLAN reveals many of the following messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[TCP Dup ACK...]&lt;/P&gt;&lt;P&gt;[TCP Retransmission...]&lt;/P&gt;&lt;P&gt;[TCP Out-Of-Order] [Continuation to #...]&lt;/P&gt;&lt;P&gt;[TCP ACKed lost segment]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone advise what's wrong with the FWSM? I can't find Release Notes of 3.1(8). Going through Release Notes of 3.1(9), I don't find any SQL-related issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;B.Rgds,&lt;/P&gt;&lt;P&gt;Lim TS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 07:41:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664445#M1028333</guid>
      <dc:creator>limtohsoon</dc:creator>
      <dc:date>2008-04-22T07:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with FWSM and SQL*Net</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664446#M1028334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.all&lt;/P&gt;&lt;P&gt;Trying remove "inspect sqlnet" on fwsm.&lt;/P&gt;&lt;P&gt;Maybe...problem solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 May 2008 16:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-fwsm-and-sql-net/m-p/664446#M1028334</guid>
      <dc:creator>capjjy</dc:creator>
      <dc:date>2008-05-16T16:50:54Z</dc:date>
    </item>
  </channel>
</rss>

