<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic At the time of issue did you in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725591#M179026</link>
    <description>&lt;P&gt;At the time of issue did you try pinging internet from the ASA?&lt;/P&gt;&lt;P&gt;Check if the interface is UP or not.&lt;/P&gt;&lt;P&gt;Check ARP entries on ASA and also check if upstream device is passing traffic at the time of issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2015 19:16:59 GMT</pubDate>
    <dc:creator>Rishabh Seth</dc:creator>
    <dc:date>2015-09-29T19:16:59Z</dc:date>
    <item>
      <title>Cisco ASA 5510 reboot necessary every week</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725581#M179016</link>
      <description>&lt;P&gt;From time to time , almost every week we have to reboot ASA firewall. Before I manually hit the button, I noticed there is no DNS communication at time we loose internet connection. Logging to CLI ASA can't ping anything to outside word from outside interface. Have already replaced hardware, CISCO TAC checked config and all should be ok. Should be. I am thinking about setting the some sort of syslog to see what is going on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA port is connected to ISP router Cisco 2800. Both port had duplex and speed set to auto. I have changed that manually. What else I can do in order to troubleshoot that?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725581#M179016</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2019-03-12T06:33:28Z</dc:date>
    </item>
    <item>
      <title>Do you have a span/monitor</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725582#M179017</link>
      <description>&lt;P&gt;Do you have a span/monitor port capable switch you can use to connect the ASA and the ISP router? This could help give you visibility by mirroring traffic to a device that has tcpdump/wireshark available for analysis.&lt;/P&gt;&lt;P&gt;Below are things I'd look at while the problem is occurring on the ASA.&lt;/P&gt;&lt;P&gt;Can you ping your ISP's side of the connection (2800)?&lt;/P&gt;&lt;P&gt;Do you have a valid arp entry to the ISP's address?&lt;/P&gt;&lt;P&gt;Aside from internet communication do other things to/from/through the ASA appear to work? LAN to DMZ communication? Ping's etc?&lt;/P&gt;&lt;P&gt;Have you checked nat, memory, and cpu resources?&lt;/P&gt;&lt;P&gt;Do you have a static IP or dynamic?&lt;/P&gt;&lt;P&gt;Do interfaces show unusual errors or drops?&lt;/P&gt;&lt;P&gt;Have you conferenced in your ISP and TAC during an outage?&lt;/P&gt;&lt;P&gt;Your ISP should also be able to troubleshoot from their equipment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2015 05:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725582#M179017</guid>
      <dc:creator>dbellaze</dc:creator>
      <dc:date>2015-09-06T05:10:08Z</dc:date>
    </item>
    <item>
      <title>Thank You, meantime I have</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725583#M179018</link>
      <description>&lt;P&gt;Thank You, meantime I have logs from syslog while all was down and could not ping 8.8.8.8.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have a static IP or dynamic? STATIC&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal; background-color: rgb(249, 249, 249);"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal; background-color: rgb(249, 249, 249);"&gt;Do interfaces show unusual errors or drops? Attached syslog.&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal; background-color: rgb(249, 249, 249);"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal; background-color: rgb(249, 249, 249);"&gt;I have feeling its either DoS, or some sort of attack. I will try to&amp;nbsp;get answers on all. Thank You.&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.4px; line-height: normal; background-color: rgb(249, 249, 249);"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 14:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725583#M179018</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-11T14:59:51Z</dc:date>
    </item>
    <item>
      <title>I have noticed its happening</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725584#M179019</link>
      <description>&lt;P&gt;I have noticed its happening every time we access NWEA site for testing. All is ok during the days we don't use that site at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 14:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725584#M179019</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-15T14:01:04Z</dc:date>
    </item>
    <item>
      <title>I found NWEA has some</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725585#M179020</link>
      <description>&lt;P&gt;I found NWEA has some references to DoS on twitter.&lt;/P&gt;&lt;P&gt;https://mobile.twitter.com/NWEA?lang=fil&lt;/P&gt;&lt;P&gt;From the post it sounds like they were attacked in some way so its possible you had/have systems in your network contributing. You mentioned testing as well, maybe a faulty or misconfigured system?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 04:06:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725585#M179020</guid>
      <dc:creator>dbellaze</dc:creator>
      <dc:date>2015-09-17T04:06:54Z</dc:date>
    </item>
    <item>
      <title>but is that possible their</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725586#M179021</link>
      <description>&lt;P&gt;but is that possible their problems affecting our network service? I don't want to believe it is possible at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 23:09:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725586#M179021</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-17T23:09:58Z</dc:date>
    </item>
    <item>
      <title>What I have done was placing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725587#M179022</link>
      <description>&lt;P&gt;What I have done was placing a switch between a router and firewall, mirrored ports and took TCPDUMP. I have a file but another problem is analyzing that file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DNS blockout happens at same times, I wonder if there is limit on ASA 5510 for client connection or sessions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2015 13:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725587#M179022</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-26T13:37:32Z</dc:date>
    </item>
    <item>
      <title>I was able to get tcpdump</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725588#M179023</link>
      <description>&lt;P&gt;I was able to get tcpdump from the time when I had to reboot ASA again. Looks like right before WAN port "die" there was a lot of https traffic but I don't think I deal with DoS since network was utilized in 48%.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I start taking tcpdump files out of internal network just before they reach ASA and behind both in and out. But this is really drives me crazy since the problem is being since 3 weeks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 00:04:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725588#M179023</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-28T00:04:08Z</dc:date>
    </item>
    <item>
      <title>What I have noticed based on</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725589#M179024</link>
      <description>&lt;P&gt;What I have noticed based on tcp dump is a lot https traffic is generated from my side to 23.4.1.138 &amp;nbsp;and 173.194.192.95, but the first one kicks before ASA WAN port dies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like this is akamai technologies. The question is how that affects and how to stop the traffic?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 15:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725589#M179024</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-29T15:55:19Z</dc:date>
    </item>
    <item>
      <title>maybe you're part of the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725590#M179025</link>
      <description>&lt;P&gt;maybe you're part of the problem &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;maybe you are one of the attackers? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; some zombies in your network?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 18:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725590#M179025</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2015-09-29T18:51:38Z</dc:date>
    </item>
    <item>
      <title>At the time of issue did you</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725591#M179026</link>
      <description>&lt;P&gt;At the time of issue did you try pinging internet from the ASA?&lt;/P&gt;&lt;P&gt;Check if the interface is UP or not.&lt;/P&gt;&lt;P&gt;Check ARP entries on ASA and also check if upstream device is passing traffic at the time of issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 19:16:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725591#M179026</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-09-29T19:16:59Z</dc:date>
    </item>
    <item>
      <title>Yes, at that time WAN port on</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725592#M179027</link>
      <description>&lt;P&gt;Yes, at that time WAN port on ASA looks like is UP - BUT I can't ping anything externally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Normally, I can ping any ip out of ASA. together with ISP we sat manually speed and duplex on both ASA and router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA &amp;gt; ROUTER (ISP)&amp;gt; switch (ISP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, If I unplug the WAN data cable from the router and plug it to the a laptop with my static info I can open any websites without issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 19:25:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725592#M179027</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-29T19:25:51Z</dc:date>
    </item>
    <item>
      <title>Hi, You have mentioned that</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725593#M179028</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have mentioned that you can span traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So at the time of issue do you see traffic leaving ASA when :&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; You try to ping public IP from ASA.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; You try to ping public IP from a host behind ASA.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; In any of the above cases do you see reply coming back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It might be possible that there is some issue with upstream device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And as you have mentioned that when you plug your laptop you do not see the issue. So did you test the connectivity with your laptop directly connected for a week? If not then probably the issue might take some time to occur.&lt;/P&gt;&lt;P&gt;Also try speed and duplex with auto if possible.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 20:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725593#M179028</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-09-29T20:02:33Z</dc:date>
    </item>
    <item>
      <title>well, I cannot use the laptop</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725594#M179029</link>
      <description>&lt;P&gt;well, I cannot use the laptop connected to my WAN link since this is a production environment. Also, for troubleshooting my time is limited since I have 700 people waiting to be online. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; I will be looking for traffic insight of network but I don't think this matters since I see bandwidth utilization for both U/D = 50%&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 12:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725594#M179029</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-30T12:43:08Z</dc:date>
    </item>
    <item>
      <title>why nobody says to use: show</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725595#M179030</link>
      <description>&lt;P&gt;why nobody says to use:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show local-host connection tcp 1000 | inc TCP flow count ?????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I hit a jock pot and narrowed it down to my problems. So one external IP is not enough to all ports an connections. I may expend that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sense? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 17:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725595#M179030</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-09-30T17:58:25Z</dc:date>
    </item>
    <item>
      <title>To check if your PAT pool is</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725596#M179031</link>
      <description>&lt;P&gt;To check if your PAT pool is getting exhausted then you can use command show nat pool and then make a decision to add more IP address for NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 18:47:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725596#M179031</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-09-30T18:47:23Z</dc:date>
    </item>
    <item>
      <title>damm it, its not the case, I</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725597#M179032</link>
      <description>&lt;P&gt;damm it, its not the case, I added extra IP as backup of existing one to external,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;according to me someone or something from internal network attaching my external IP, rather looking on the syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way on ASA see what internal IP is messing with external IP?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 23:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725597#M179032</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-10-01T23:29:25Z</dc:date>
    </item>
    <item>
      <title>can you try following at the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725598#M179033</link>
      <description>&lt;P&gt;can you try following at the time of issue:&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; ping any hostname from ASA and capture traffic to see if the outgoing traffic is getting source translated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; Ping your default gateway to ensure upstream device is is reachable.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; There could be come problem with upstream device on layer two. Try applying capture for ARP at the time of issue and check if you anything unusual.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; instead of reloading ASA, try bouncing interface connected to upstream device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let us know your findings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;R Seth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 09:36:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725598#M179033</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-02T09:36:05Z</dc:date>
    </item>
    <item>
      <title>sorry for a confusion, what</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725599#M179034</link>
      <description>&lt;P&gt;sorry for a confusion, what you mean "&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;try bouncing interface connected to upstream device" &amp;nbsp;?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 12:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725599#M179034</guid>
      <dc:creator>sprintership-il</dc:creator>
      <dc:date>2015-10-02T12:04:23Z</dc:date>
    </item>
    <item>
      <title>Try shut and no shut of</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725600#M179035</link>
      <description>&lt;P&gt;Try shut and no shut of interface connected to ISP device or unplug and plug tha cable from ASA which is connected to ISP device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 12:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-reboot-necessary-every-week/m-p/2725600#M179035</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-02T12:12:59Z</dc:date>
    </item>
  </channel>
</rss>

