<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Abnormal behavior of ASA when adding policy-map type inspect esmtp in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5240859#M1118435</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1506747"&gt;@kz-support&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ESMTP is inspected by default in ASA. Did you tried to reaply the config to make sure It was really the problem?&lt;/P&gt;</description>
    <pubDate>Thu, 26 Dec 2024 10:02:00 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2024-12-26T10:02:00Z</dc:date>
    <item>
      <title>Abnormal behavior of ASA when adding policy-map type inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5240503#M1118423</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;two cisco asa (FTD 2130 in appliance mode) work in failover pair&lt;/P&gt;
&lt;P&gt;I tried to add a new smtp traffic inspection policy via ssh console&lt;/P&gt;
&lt;P&gt;policy-map type inspect esmtp quik_no_ehlo_mask&lt;BR /&gt;description do not mask ehlo for quik servers&lt;BR /&gt;parameters&lt;BR /&gt;mask-banner&lt;BR /&gt;no mail-relay&lt;BR /&gt;no special-character&lt;BR /&gt;allow-tls&lt;BR /&gt;exi&lt;BR /&gt;match cmd line length gt 512&lt;BR /&gt;drop-connection log&lt;BR /&gt;match cmd RCPT count gt 100&lt;BR /&gt;drop-connection log&lt;BR /&gt;match body line length gt 998&lt;BR /&gt;log&lt;/P&gt;
&lt;P&gt;After entering the last command, my ssh console stops responding (access was restored after a few minutes) and alerts of the following type start pouring in from standby asa every 15 seconds&lt;/P&gt;
&lt;P&gt;Nov 12, 2024 @ 12:25:04.000 ASA %ASA-1-105005: (Secondary) Lost Failover communications with mate on interface mex&lt;BR /&gt;Nov 12, 2024 @ 12:25:04.000 ASA %ASA-1-105008: (Secondary) Testing Interface mex&lt;BR /&gt;Nov 12, 2024 @ 12:25:04.000 ASA %ASA-1-105009: (Secondary) Testing on interface mex Passed&lt;/P&gt;
&lt;P&gt;Such messages come about all interfaces on failover monitoring&lt;/P&gt;
&lt;P&gt;I logged into asa via the console port, tried to delete the policy&lt;BR /&gt;no policy-map type inspect esmtp quik_no_ehlo_mask&lt;BR /&gt;ERROR: policy-map quik_no_ehlo_mask is being configured and hence cannot be removed.&lt;/P&gt;
&lt;P&gt;At the same time, there were no problems with passing traffic through the primary ASA and failover did not work either. Only messages from the standby ASA monitoring were constantly coming as above.&lt;/P&gt;
&lt;P&gt;There was also no increased CPU or memory load.&lt;/P&gt;
&lt;P&gt;At 13:18, the problem resolved itself. Alerts stopped coming. I logged in via ssh and deleted the policy without spaces.&lt;/P&gt;
&lt;P&gt;I did not find any other errors in the log during this time, except for the fact that ACS dropped the ssh session immediately after the problem began.&lt;/P&gt;
&lt;P&gt;Nov 12, 2024 @ 12:25:05.000 ASA %ASA-6-725007: SSL session with client inside:10.0.0.148/51723 to 172.16.0.10/443 terminated&lt;BR /&gt;Nov 12, 2024 @ 12:25:05.000 ASA %ASA-6-725001: Starting SSL handshake with client inside:10.0.0.148/51724 to 172.16.0.10/443 for TLS session&lt;BR /&gt;Nov 12, 2024 @ 12:25:05.000 ASA %ASA-6-725016: Device selects trust-point ASA-self-signed for client inside:10.0.0.148/51724 to 1172.16.0.10/443&lt;BR /&gt;Nov 12, 2024 @ 12:25:05.000 ASA %ASA-6-725002: Device completed SSL handshake with client inside:10.0.0.148/51724 to 172.16.0.10/443 for TLSv1.2 session&lt;BR /&gt;Nov 12, 2024 @ 12:25:05.000 ASA %ASA-6-725007: SSL session with client inside:10.0.0.148/51724 to 172.16.0.10/443 terminated&lt;BR /&gt;Nov 12, 2024 @ 12:25:05.000 ASA %ASA-6-725001: Starting SSL handshake with client inside:10.0.0.148/51725 to 172.16.0.10/443 for TLS session&lt;BR /&gt;Nov 12, 2024 @ 12:25:05.000 ASA %ASA-6-725016: Device selects trust-point ASA-self-signed for client inside:10.0.0.148/51725 to 172.16.0.10/443&lt;BR /&gt;Nov 12, 2024 @ 12:25:05.000 ASA %ASA-6-725002: Device completed SSL handshake with client inside:10.0.0.148/51725 to 172.16.0.10/443 for TLSv1.2 session&lt;/P&gt;
&lt;P&gt;Please help with diagnostics of this behavior.&lt;/P&gt;
&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.14(4)17&lt;BR /&gt;SSP Operating System Version 2.8(1.191)&lt;BR /&gt;Device Manager Version 7.19(1)95&lt;/P&gt;
&lt;P&gt;Compiled on Wed 19-Oct-22 06:12 GMT by builders&lt;BR /&gt;System image file is "disk0:/mnt/boot/installables/switch/fxos-k8-fp2k-npu.2.8.1.191.SPA"&lt;BR /&gt;Config file at boot was "startup-config"&lt;/P&gt;
&lt;P&gt;ASA up 1 year 64 days&lt;BR /&gt;failover cluster up 2 years 115 days&lt;/P&gt;
&lt;P&gt;Hardware: FPR-2130, 13703 MB RAM, CPU MIPS 1200 MHz, 1 CPU (12 cores)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you help me to troubleshoot it?&lt;/P&gt;
&lt;P&gt;Tthank you in advance&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 16:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5240503#M1118423</guid>
      <dc:creator>kz-support</dc:creator>
      <dc:date>2024-12-24T16:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Abnormal behavior of ASA when adding policy-map type inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5240843#M1118432</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Your issue with the ASA might be related to resource contention or configuration conflicts triggered by the policy-map. The recurring failover communication loss messages suggest instability, possibly due to a problem with the failover interface or the complex policy.&lt;/P&gt;&lt;P&gt;Check the failover interface and verify physical connectivity.&lt;BR /&gt;Run debug logs to capture more detailed information about what happens when the policy is added.&lt;BR /&gt;Simplify or remove the policy-map temporarily to see if it resolves the issue.&lt;BR /&gt;Ensure ASA software is up to date and check for any known bugs.&lt;BR /&gt;If this doesn’t help, consider opening a case with Cisco TAC for more targeted troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cashnetusaus.com" target="_self"&gt;&lt;FONT size="1 2 3 4 5 6 7" color="#FFFFFF"&gt;CashNetUSA loans&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 05:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5240843#M1118432</guid>
      <dc:creator>faruk74summy</dc:creator>
      <dc:date>2024-12-27T05:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: Abnormal behavior of ASA when adding policy-map type inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5240859#M1118435</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1506747"&gt;@kz-support&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ESMTP is inspected by default in ASA. Did you tried to reaply the config to make sure It was really the problem?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2024 10:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5240859#M1118435</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-26T10:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Abnormal behavior of ASA when adding policy-map type inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5241466#M1118471</link>
      <description>&lt;P&gt;I don't know if there&amp;nbsp; were such policy or not, but I noticed many messages ' /opt/bootcli/cisco/cli/bin/fxos_ntpd_monitor.sh: line 87: echo: write error: No space left on device' in stdout_ntp_fxos.log file. And indeed&amp;nbsp; I see the partition&amp;nbsp;&lt;SPAN&gt;opt_cisco_platform_logs is full and must be cleared&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;firepower-2130 /fabric-interconnect # show storage&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Storage on local flash drive of fabric interconnect:&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Partition&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size (MBytes)&amp;nbsp;&amp;nbsp;&amp;nbsp; Used Percentage&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---------------- ---------------- ---------------&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mnt_boot&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7500&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; opt_cisco_config 922&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; opt_cisco_csp&amp;nbsp;&amp;nbsp;&amp;nbsp; 160142&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; opt_cisco_platfo 921&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Full&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; usbdrive&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Nothing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Empty&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; var_data_cores&amp;nbsp;&amp;nbsp; 28033&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;firepower-2130 /fabric-interconnect # show storage detail&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Storage on local flash drive of fabric interconnect:&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Partition: mnt_boot&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size (MBytes): 7500&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Used Percentage: 21&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Partition: opt_cisco_config&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size (MBytes): 922&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Used Percentage: 30&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Partition: opt_cisco_csp&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size (MBytes): 160142&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Used Percentage: 2&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Most likely this is the problem, in any case it needs to be solved first&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Partition: opt_cisco_platform_logs&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size (MBytes): 921&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Used Percentage: Full&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Partition: usbdrive&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size (MBytes): Nothing&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Used Percentage: Empty&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Partition: var_data_cores&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Size (MBytes): 28033&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Used Percentage: 1&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;I suppose if we can't&amp;nbsp;&amp;nbsp;secure-login to linux shell without Cisco TAC to clear pertition, we can do that by formatting or reimaging like it described in this link&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/troubleshoot/asa-fxos-troubleshoot/system_recovery.html#task_tfx_dtm_tgb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/troubleshoot/asa-fxos-troubleshoot/system_recovery.html#task_tfx_dtm_tgb&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 10:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5241466#M1118471</guid>
      <dc:creator>kz-support</dc:creator>
      <dc:date>2024-12-28T10:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Abnormal behavior of ASA when adding policy-map type inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5263134#M1119689</link>
      <description>&lt;P&gt;We formated disk during the Reformat procedure&lt;/P&gt;
&lt;P&gt;The problem with free space in the opt_cisco_platform_logs folder has been solved.&lt;/P&gt;
&lt;P&gt;We also configured policy-map after the work. There were no problems.&lt;/P&gt;
&lt;P&gt;However, during the Reformat procedure we encountered with the next problem:&lt;/P&gt;
&lt;P&gt;We format the disk on the standby node. It reboots and boots with an empty config&lt;/P&gt;
&lt;P&gt;We configure the failover settings and enable it&lt;/P&gt;
&lt;P&gt;The two devices Active and Standby correctly see each other and the active node begins synchronizing the config with the secondary one.&lt;/P&gt;
&lt;P&gt;After synchronization is complete, the problem appear with the interfaces for which monitoring is configured not switching to the "Monitored" status but remaining in the "Waiting" status&lt;/P&gt;
&lt;P&gt;There is spam in the logs&lt;BR /&gt;Testing Interface XXX&lt;BR /&gt;Testing on interface XXX Passed&lt;/P&gt;
&lt;P&gt;Testing Interface XXX&lt;BR /&gt;Testing on interface XXX Passed&lt;/P&gt;
&lt;P&gt;We solved the problem by sending the standby node to reboot again and after rebooting, failover was correctly assembled.&lt;/P&gt;
&lt;P&gt;The failover switching procedure also worked correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could somebody tells me whats wrong?&lt;/P&gt;
&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 16:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/abnormal-behavior-of-asa-when-adding-policy-map-type-inspect/m-p/5263134#M1119689</guid>
      <dc:creator>kz-support</dc:creator>
      <dc:date>2025-02-20T16:18:48Z</dc:date>
    </item>
  </channel>
</rss>

