<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5585-x and sqlnet connectivity failure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086242#M133514</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Hello&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;We have replaced our FWSM with the cisco ASA 5585-x (SSP-60).We have configured them in cluster mode. But &lt;SPAN style="color: #333333;"&gt;some Oracle applications are losing connectivity to the database&lt;/SPAN&gt; after replacement of Firewalls, Frequently&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;The error on the application server is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;“Failed getting connection - at oradatabase.cpp(101) ORA-12547 : TNS: lost contact”&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;And error on the ASA is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;“Deny TCP (no connection) from &lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: red;"&gt;appserver_ip&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;/54864 to &lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: red;"&gt;database_server_ip&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;/1521 flags FIN ACK on interface &lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: red;"&gt;Application_server_interface.”&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;The first thing we created IP ANY ANY rules on the interface that belongs to applications.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;According to forum suggestions, we have disabled SQLNET global policy inspection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;The next thing, we have created a service policy (interface base) to match our application to database connection on TCP/1521 protocol.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Then we have setted up TCP connection properties on those streams to include the following details:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;Timeout=0:00:00&lt;/SPAN&gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;unlimited&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;Reset enabled&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;DCD enabled&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;Retry interval 00:15:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;Retry times=5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="line-height: 15.0pt; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;We also have configured TCP map in the TCP normalization options on that:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Setted the reserved bits on “Allow only”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the "Clear Urgent flag" to allow URG flags&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop Connection on window variation”.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop Packets that exceed maximum segment size”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “check if retransmitted data is the same as original”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop SYN packets with data”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Enable TTL evasion protection.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Verify TCP checksum”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop SYNACK packets with data”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop packets with invalid ACK”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;And in TCP option just “clear window scale” has enabled.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Does inspection on SQLNET ineffect by disabling SQLNET global policy inspection?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;What‘s wrong with us?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="line-height: 15.0pt; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white; margin: 0in 0in 16.8pt 0in;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white; outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial; word-spacing: 0px; margin: 0in 0in 16.8pt 0in;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:46:29 GMT</pubDate>
    <dc:creator>MKH</dc:creator>
    <dc:date>2019-03-12T09:46:29Z</dc:date>
    <item>
      <title>ASA 5585-x and sqlnet connectivity failure</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086242#M133514</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Hello&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;We have replaced our FWSM with the cisco ASA 5585-x (SSP-60).We have configured them in cluster mode. But &lt;SPAN style="color: #333333;"&gt;some Oracle applications are losing connectivity to the database&lt;/SPAN&gt; after replacement of Firewalls, Frequently&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;The error on the application server is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;“Failed getting connection - at oradatabase.cpp(101) ORA-12547 : TNS: lost contact”&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;And error on the ASA is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;“Deny TCP (no connection) from &lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: red;"&gt;appserver_ip&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;/54864 to &lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: red;"&gt;database_server_ip&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: #333333;"&gt;/1521 flags FIN ACK on interface &lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 115%; font-family: 'Arial','sans-serif'; color: red;"&gt;Application_server_interface.”&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;The first thing we created IP ANY ANY rules on the interface that belongs to applications.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;According to forum suggestions, we have disabled SQLNET global policy inspection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;The next thing, we have created a service policy (interface base) to match our application to database connection on TCP/1521 protocol.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Then we have setted up TCP connection properties on those streams to include the following details:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;Timeout=0:00:00&lt;/SPAN&gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;unlimited&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;Reset enabled&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;DCD enabled&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;Retry interval 00:15:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; line-height: 15.0pt; tab-stops: list 1.0in; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;Retry times=5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="line-height: 15.0pt; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;We also have configured TCP map in the TCP normalization options on that:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Setted the reserved bits on “Allow only”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the "Clear Urgent flag" to allow URG flags&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop Connection on window variation”.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop Packets that exceed maximum segment size”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “check if retransmitted data is the same as original”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop SYN packets with data”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Enable TTL evasion protection.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Verify TCP checksum”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop SYNACK packets with data”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="text-indent: -.25in; outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&lt;SPAN style="font: 7.0pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Disabled the “Drop packets with invalid ACK”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="outline: none;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;And in TCP option just “clear window scale” has enabled.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Does inspection on SQLNET ineffect by disabling SQLNET global policy inspection?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;What‘s wrong with us?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; line-height: 115%; font-family: 'Times New Roman','serif';"&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="line-height: 15.0pt; background: white; outline: none; margin: 0in 0in .0001pt 37.5pt;"&gt;&lt;SPAN style="outline: none;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white; margin: 0in 0in 16.8pt 0in;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white; outline: none; font-variant-ligatures: normal; font-variant-caps: normal; orphans: 2; text-align: start; widows: 2; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial; word-spacing: 0px; margin: 0in 0in 16.8pt 0in;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif'; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086242#M133514</guid>
      <dc:creator>MKH</dc:creator>
      <dc:date>2019-03-12T09:46:29Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086243#M133516</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please share the output of show run policy-map and show service-policy.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 04:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086243#M133516</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-04T04:41:10Z</dc:date>
    </item>
    <item>
      <title>Hello</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086244#M133518</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Please find attached file.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 07:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086244#M133518</guid>
      <dc:creator>MKH</dc:creator>
      <dc:date>2017-08-04T07:39:20Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086245#M133520</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see the service-policy is applied on two different interfaces:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;policy-map &lt;G class="gr_ gr_64 gr-alert gr_spell gr_inline_cards gr_disable_anim_appear ContextualSpelling ins-del multiReplace" id="64" data-gr-id="64"&gt;Fruad&lt;/G&gt;-Web/App-Service-policy&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;policy-map Interconnect-Billing-DB-policy&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you let me know which is the one that is facing an issue?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 09:21:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086245#M133520</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-04T09:21:07Z</dc:date>
    </item>
    <item>
      <title>Hello</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086246#M133522</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The policy-map &lt;EM&gt;Fruad-Web/App-Service-policy&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;have confronted with problem.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 09:54:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-x-and-sqlnet-connectivity-failure/m-p/3086246#M133522</guid>
      <dc:creator>MKH</dc:creator>
      <dc:date>2017-08-04T09:54:04Z</dc:date>
    </item>
  </channel>
</rss>

