<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA has problem with SSL config in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5553390#M1125220</link>
    <description>&lt;P&gt;The cause is called Elephant Flow, and we found that the issue is on the outside interface of the FPR1010-ASA.&amp;nbsp; Packets are being dropped at a large amount.&amp;nbsp; From my BR I did a trace and found ICMP and UDP drop at over 39%.&amp;nbsp; But let me explain more! We are using ASA's to also route EIGRP across the network.&amp;nbsp; In this scenario I have two ASA's before I connect to the core switch.&amp;nbsp; So basically, I have an ASA at one location that I connect via the outside interface to another ASAs inside interface.&amp;nbsp; With NO redistribution on either device.&amp;nbsp; Strange I know, yet traffic flows thru both to core switch. When LARGE traffic or images transverses the connection it gives a jitter.&amp;nbsp; My question is should I put a redistribution on the ASAs or configure a NAT to allow all traffic to core?&lt;/P&gt;</description>
    <pubDate>Mon, 18 May 2026 13:45:51 GMT</pubDate>
    <dc:creator>RANT</dc:creator>
    <dc:date>2026-05-18T13:45:51Z</dc:date>
    <item>
      <title>ASA has problem with SSL config</title>
      <link>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5549588#M1125130</link>
      <description>&lt;P&gt;Have FPR1010 that connects to c2960 and drops SSL when user tries to launch program.&amp;nbsp; Switch shows one class-map with errors and User states getting errors.&amp;nbsp; "&lt;SPAN&gt;The error &lt;I&gt;SSL connect error (openssl ssl_connect: ssl_error_syscall)&lt;/I&gt; indicates that the TLS handshake between your client and the server failed, often due to certificate issues, protocol mismatches, or network interruptions."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Real error is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 21:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5549588#M1125130</guid>
      <dc:creator>RANT</dc:creator>
      <dc:date>2026-04-30T21:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA has problem with SSL config</title>
      <link>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5549649#M1125131</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244921"&gt;@RANT&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; What are you trying https or SSL ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2026 06:40:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5549649#M1125131</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2026-05-01T06:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA has problem with SSL config</title>
      <link>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5549658#M1125132</link>
      <description>&lt;P&gt;Could you please share your sanitized configs and topology for review?&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2026 08:30:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5549658#M1125132</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2026-05-01T08:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA has problem with SSL config</title>
      <link>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5549842#M1125134</link>
      <description>&lt;P&gt;two possibilities come to my mind&lt;BR /&gt;1) the FPR uses SSL inspection ( man in the middle of the SSL link)&lt;BR /&gt;2) the FPR recognizes the used protocol (more specific than only SSL) to the "render server" but is not configured to forward this.&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2026 10:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5549842#M1125134</guid>
      <dc:creator>pieterh</dc:creator>
      <dc:date>2026-05-02T10:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA has problem with SSL config</title>
      <link>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5553390#M1125220</link>
      <description>&lt;P&gt;The cause is called Elephant Flow, and we found that the issue is on the outside interface of the FPR1010-ASA.&amp;nbsp; Packets are being dropped at a large amount.&amp;nbsp; From my BR I did a trace and found ICMP and UDP drop at over 39%.&amp;nbsp; But let me explain more! We are using ASA's to also route EIGRP across the network.&amp;nbsp; In this scenario I have two ASA's before I connect to the core switch.&amp;nbsp; So basically, I have an ASA at one location that I connect via the outside interface to another ASAs inside interface.&amp;nbsp; With NO redistribution on either device.&amp;nbsp; Strange I know, yet traffic flows thru both to core switch. When LARGE traffic or images transverses the connection it gives a jitter.&amp;nbsp; My question is should I put a redistribution on the ASAs or configure a NAT to allow all traffic to core?&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2026 13:45:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5553390#M1125220</guid>
      <dc:creator>RANT</dc:creator>
      <dc:date>2026-05-18T13:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA has problem with SSL config</title>
      <link>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5553900#M1125234</link>
      <description>&lt;P&gt;I don't believe redistribution or NAT would play any role here because from what you explained the traffic is not fully dropped, some passes and some not. I believe it might be an issue with the firewalls resources that can't cope with that amount of traffic?&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 08:27:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-has-problem-with-ssl-config/m-p/5553900#M1125234</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2026-05-20T08:27:11Z</dc:date>
    </item>
  </channel>
</rss>

