<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Возможно лог на ASA хоть in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858265#M159447</link>
    <description>&lt;P&gt;Возможно лог на ASA хоть немного прояснит ситуацию. А так идей нету.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2016 15:58:02 GMT</pubDate>
    <dc:creator>vovik1233</dc:creator>
    <dc:date>2016-02-17T15:58:02Z</dc:date>
    <item>
      <title>ASA 5525-X problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858264#M159443</link>
      <description>&lt;P&gt;Добрый день столкнулся с проблемой при настройке BGP на ASA 5525-x, суть проблемы в том что спустя некоторые время она начинает дропать некоторые сайты к примеру fs.to, gismeteo.ua и перестает грузиться видео на youtube, ставлю mtu меньше некоторое время сайты эти работают потом перестают, отправлял пакет http через ASA PT, то он проходит, куда смотреть я не знаю, кто сталкивался с такой проблемой, нужна помощь(версии все перепробовал не помогло)?&lt;BR /&gt;пример конфига вот:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ASA Version 9.5(1)&lt;BR /&gt;!&lt;BR /&gt;hostname RouterBGP&lt;BR /&gt;domain-name domain.net&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;flowcontrol send on&lt;BR /&gt;nameif prov1&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 10.1.10.3 255.255.255.248&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;flowcontrol send on&lt;BR /&gt;nameif prov2&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 198.168.20.5 255.255.255.248&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;flowcontrol send on&lt;BR /&gt;nameif dmz&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 10.11.29.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;flowcontrol send on&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/4&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/6&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/7&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;management-only&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address a.b.c.d a.b.c.d&lt;BR /&gt;!&lt;BR /&gt;boot config disk0:/admin.cfg&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;domain-name domain.net&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging trap warnings&lt;BR /&gt;logging host management a.b.c.d&lt;BR /&gt;mtu prov1 1500&lt;BR /&gt;mtu prov2 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;no failover&lt;BR /&gt;no monitor-interface service-module&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;!&lt;BR /&gt;prefix-list Anons seq 5 permit 10.11.29.0/24&lt;BR /&gt;!&lt;BR /&gt;prefix-list default seq 5 permit 0.0.0.0/0&lt;BR /&gt;!&lt;BR /&gt;bgp-community new-format&lt;BR /&gt;!&lt;BR /&gt;route-map Uran-output permit 100&lt;BR /&gt;match ip address prefix-list Anons&lt;BR /&gt;!&lt;BR /&gt;route-map Ukrcom-output permit 100&lt;BR /&gt;match ip address prefix-list Anons&lt;BR /&gt;set as-path prepend 197000 197000 197000 197000 197000&lt;BR /&gt;set community 21000:20005 21000:30005 21000:40005&lt;BR /&gt;!&lt;BR /&gt;route-map Default permit 100&lt;BR /&gt;match ip address prefix-list default&lt;BR /&gt;!&lt;BR /&gt;router bgp 197000&lt;BR /&gt;bgp log-neighbor-changes&lt;BR /&gt;bgp bestpath compare-routerid&lt;BR /&gt;no bgp enforce-first-as&lt;BR /&gt;bgp router-id 10.11.29.1&lt;BR /&gt;address-family ipv4 unicast&lt;BR /&gt;neighbor 198.168.20.6 remote-as 21000&lt;BR /&gt;neighbor 198.168.20.6 description Ukrcom&lt;BR /&gt;neighbor 198.168.20.6 activate&lt;BR /&gt;neighbor 198.168.20.6 send-community&lt;BR /&gt;neighbor 198.168.20.6 next-hop-self&lt;BR /&gt;neighbor 198.168.20.6 weight 200&lt;BR /&gt;neighbor 198.168.20.6 route-map Default in&lt;BR /&gt;neighbor 198.168.20.6 route-map Ukrcom-output out&lt;BR /&gt;neighbor 10.1.10.2 remote-as 12000&lt;BR /&gt;neighbor 10.1.10.2 description Uran&lt;BR /&gt;neighbor 10.1.10.2 activate&lt;BR /&gt;neighbor 10.1.10.2 next-hop-self&lt;BR /&gt;neighbor 10.1.10.2 weight 500&lt;BR /&gt;neighbor 10.1.10.2 route-map Default in&lt;BR /&gt;neighbor 10.1.10.2 route-map Uran-output out&lt;BR /&gt;network 10.11.29.0&lt;BR /&gt;no auto-summary&lt;BR /&gt;no synchronization&lt;BR /&gt;exit-address-family&lt;BR /&gt;!&lt;BR /&gt;route prov1 0.0.0.0 0.0.0.0 10.1.10.2 1&lt;BR /&gt;route prov2 0.0.0.0 0.0.0.0 198.168.20.6 2&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;snmp-server group cactus v3 auth&lt;BR /&gt;snmp-server host management a.b.c.d community ***** udp-port 161&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh a.b.c.d a.b.c.d management&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server a.b.c.d source management&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns migrated_dns_map_1&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns migrated_dns_map_1&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect icmp&lt;BR /&gt;inspect icmp error&lt;BR /&gt;inspect http&lt;BR /&gt;!&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymou&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858264#M159443</guid>
      <dc:creator>deadlove1992</dc:creator>
      <dc:date>2019-03-12T07:19:04Z</dc:date>
    </item>
    <item>
      <title>Возможно лог на ASA хоть</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858265#M159447</link>
      <description>&lt;P&gt;Возможно лог на ASA хоть немного прояснит ситуацию. А так идей нету.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2016 15:58:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858265#M159447</guid>
      <dc:creator>vovik1233</dc:creator>
      <dc:date>2016-02-17T15:58:02Z</dc:date>
    </item>
    <item>
      <title>packet-tracer input dmz tcp</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858266#M159453</link>
      <description>&lt;DIV&gt;packet-tracer input dmz tcp 10.11.29.185 http 91.226.97.14 http&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Phase: 1&lt;/DIV&gt;
&lt;DIV&gt;Type: ROUTE-LOOKUP&lt;/DIV&gt;
&lt;DIV&gt;Subtype: Resolve Egress Interface&lt;/DIV&gt;
&lt;DIV&gt;Result: ALLOW&lt;/DIV&gt;
&lt;DIV&gt;Config:&lt;/DIV&gt;
&lt;DIV&gt;Additional Information:&lt;/DIV&gt;
&lt;DIV&gt;found next-hop 10.1.10.2 using egress ifc &amp;nbsp;prov1&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Phase: 2&lt;/DIV&gt;
&lt;DIV&gt;Type: ACCESS-LIST&lt;/DIV&gt;
&lt;DIV&gt;Subtype: log&lt;/DIV&gt;
&lt;DIV&gt;Result: ALLOW&lt;/DIV&gt;
&lt;DIV&gt;Config:&lt;/DIV&gt;
&lt;DIV&gt;access-group Traffic global&lt;/DIV&gt;
&lt;DIV&gt;access-list Traffic extended permit ip any4 any4&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Additional Information:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Phase: 3&lt;/DIV&gt;
&lt;DIV&gt;Type: NAT&lt;/DIV&gt;
&lt;DIV&gt;Subtype: per-session&lt;/DIV&gt;
&lt;DIV&gt;Result: ALLOW&lt;/DIV&gt;
&lt;DIV&gt;Config:&lt;/DIV&gt;
&lt;DIV&gt;Additional Information:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Phase: 4 &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Type: IP-OPTIONS&lt;/DIV&gt;
&lt;DIV&gt;Subtype:&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Result: ALLOW&lt;/DIV&gt;
&lt;DIV&gt;Config:&lt;/DIV&gt;
&lt;DIV&gt;Additional Information:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Phase: 5&lt;/DIV&gt;
&lt;DIV&gt;Type: NAT&lt;/DIV&gt;
&lt;DIV&gt;Subtype: per-session&lt;/DIV&gt;
&lt;DIV&gt;Result: ALLOW&lt;/DIV&gt;
&lt;DIV&gt;Config:&lt;/DIV&gt;
&lt;DIV&gt;Additional Information:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Phase: 6&lt;/DIV&gt;
&lt;DIV&gt;Type: IP-OPTIONS&lt;/DIV&gt;
&lt;DIV&gt;Subtype:&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Result: ALLOW&lt;/DIV&gt;
&lt;DIV&gt;Config:&lt;/DIV&gt;
&lt;DIV&gt;Additional Information:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Phase: 7&lt;/DIV&gt;
&lt;DIV&gt;Type: FLOW-CREATION&lt;/DIV&gt;
&lt;DIV&gt;Subtype:&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Result: ALLOW&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Config:&lt;/DIV&gt;
&lt;DIV&gt;Additional Information:&lt;/DIV&gt;
&lt;DIV&gt;New flow created with id 5433727, packet dispatched to next module&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Result:&lt;/DIV&gt;
&lt;DIV&gt;output-interface: prov1&lt;/DIV&gt;
&lt;DIV&gt;output-status: up&lt;/DIV&gt;
&lt;DIV&gt;output-line-status: up&lt;/DIV&gt;
&lt;DIV&gt;Action: allow&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;но запись в таблице asp выглядит так&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;TCP dmz: 10.11.29.19/63531 prov1: 91.226.97.14/80,&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; &amp;nbsp; flags SaAB , idle 0s, uptime 0s, timeout 30s, bytes 0&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;а вот ее дропы&lt;/P&gt;
&lt;DIV&gt;Frame drop:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Invalid TCP Length (invalid-tcp-hdr-length) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Invalid UDP Length (invalid-udp-length) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 98&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; No valid adjacency (no-adjacency) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 6919&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; No route to host (no-route) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1102&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Flow is denied by configured rule (acl-drop) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1133629&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; First TCP packet not SYN (tcp-not-syn) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;65151&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Bad TCP flags (bad-tcp-flags) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 89&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; TCP Dual open denied (tcp-dual-open) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 172&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; TCP data send after FIN (tcp-data-past-fin) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; TCP failed 3 way handshake (tcp-3whs-failed) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;236&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; TCP RST/FIN out of order (tcp-rstfin-ooo) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 6706&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; TCP SEQ in SYN/SYNACK invalid (tcp-seq-syn-diff) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;50&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; TCP SYNACK on established conn (tcp-synack-ooo) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; TCP packet SEQ past window (tcp-seq-past-win) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;492&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; TCP RST/SYN in window (tcp-rst-syn-in-win) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 149&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Slowpath security checks failed (sp-security-failed) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 754&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; DNS Inspect invalid packet (inspect-dns-invalid-pak) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; DNS Inspect invalid domain label (inspect-dns-invalid-domain-label) &amp;nbsp; &amp;nbsp; &amp;nbsp; 2107&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; DNS Inspect packet too long (inspect-dns-pak-too-long) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3395&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; DNS Inspect id not matched (inspect-dns-id-not-matched) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2026&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; FP L2 rule drop (l2_acl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 284&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Interface is down (interface-down) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4&lt;/DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;логи сейчас переберу последние, и выложу&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Feb 2016 17:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858266#M159453</guid>
      <dc:creator>deadlove1992</dc:creator>
      <dc:date>2016-02-17T17:50:05Z</dc:date>
    </item>
    <item>
      <title>вот часть логов</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858267#M159456</link>
      <description>&lt;P&gt;вот часть логов&lt;/P&gt;
&lt;P&gt;No matching connection for ICMP error message: icmp src dmz:212.111.209.68 dst prov1:199.254.63.254 (type 3, code 3) on dmz interface. Original IP payload: udp src 199.254.63.254/53 dst 21$&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feb 10 11:31:52 192.168.100.190 %ASA-4-410001: Dropped UDP DNS request from dmz:212.111.209.21/56988 to prov1:104.192.108.120/53; packet length 858 bytes exceeds configured limit of 512 bytes&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feb 10 11:31:52 192.168.100.190 %ASA-4-410001: Dropped UDP DNS reply from dmz:212.111.209.91/53 to prov1:121.137.48.91/60256; packet length 3993 bytes exceeds configured limit of 512 bytes&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feb 10 11:31:52 192.168.100.190 %ASA-4-410001: message repeated 5 times: [ Dropped UDP DNS reply from dmz:212.111.209.91/53 to prov1:121.137.48.91/60256; packet length 3993 bytes exceeds configured limit of 512 bytes]&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feb 10 11:31:52 192.168.100.190 %ASA-2-106016: Deny IP spoof from (0.0.0.0) to 212.111.209.21 on interface prov1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feb 10 11:31:52 192.168.100.190 %ASA-4-209005: Discard IP fragment set with more than 24 elements: src = 212.111.209.8, dest =&lt;STRONG&gt; 91.226.97.14&lt;/STRONG&gt;, proto = ICMP, id = 49892&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feb 10 11:31:53 192.168.100.190 %ASA-4-410001: Dropped UDP DNS reply from dmz:212.111.209.91/53 to prov1:121.137.48.91/16035; packet length 3993 bytes exceeds configured limit of 512 bytes&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Feb 10 11:31:53 192.168.100.190 %ASA-4-410001: message repeated 13 times: [ Dropped UDP DNS reply from dmz:212.111.209.91/53 to prov1:121.137.48.91/16035; packet length 3993 bytes exceeds configured limit of 512 bytes]&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2016 18:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858267#M159456</guid>
      <dc:creator>deadlove1992</dc:creator>
      <dc:date>2016-02-17T18:08:58Z</dc:date>
    </item>
    <item>
      <title>Бросается в глаза запись с</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858268#M159468</link>
      <description>&lt;P&gt;Бросается в глаза запись с логов:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;... packet length 3993 bytes exceeds configured limit of 512 bytes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Возможно это както поможет&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;https://supportforums.cisco.com/discussion/10172111/dns-dropped-because-packets-big-configured-512&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2016 19:58:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858268#M159468</guid>
      <dc:creator>vovik1233</dc:creator>
      <dc:date>2016-02-17T19:58:58Z</dc:date>
    </item>
    <item>
      <title>Спасибо, завтра переключусь</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858269#M159474</link>
      <description>&lt;P&gt;Спасибо, завтра переключусь посмотрю будут изменения или нет)))&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2016 20:45:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-problems/m-p/2858269#M159474</guid>
      <dc:creator>deadlove1992</dc:creator>
      <dc:date>2016-02-17T20:45:51Z</dc:date>
    </item>
  </channel>
</rss>

