<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Are you using ScanSafe or any in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-cannot-access-some-https-websites/m-p/2686018#M193689</link>
    <description>&lt;P&gt;Are you using ScanSafe or any other type of URL filtering?&lt;/P&gt;&lt;P&gt;The TCP Reset-O flag indicates that the ASA is receiving the TCP-reset.&amp;nbsp; I agree with Vibhor that you should take a look at either the server or any URL filters if you are using any.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Sat, 18 Jul 2015 06:56:24 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2015-07-18T06:56:24Z</dc:date>
    <item>
      <title>Cisco ASA 5505 - Cannot access some https websites.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-cannot-access-some-https-websites/m-p/2686016#M193686</link>
      <description>&lt;P&gt;We're having an issue with a server behind an ASA 5505 not being able to access SOME https websites, for example, &lt;A href="https://cloudcare.avg.com" target="_blank"&gt;https://cloudcare.avg.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;We have moved the server directly to the WAN and can access the website there so we believe this to be an ASA issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASDM Log when we try to open the connection on the server to &lt;A href="https://cloudcare.avg.com" target="_blank"&gt;https://cloudcare.avg.com&lt;/A&gt; (IP:&lt;SPAN style="color: rgb(34, 34, 34); font-family: verdana, arial, helvetica, sans-serif; font-size: 14px; background-color: rgb(250, 250, 250);"&gt;204.193.144.91)&lt;/SPAN&gt;&amp;nbsp;&lt;A href="http://pastebin.com/eZN7X6uh" target="_blank"&gt;http://pastebin.com/eZN7X6uh&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Packet Tracer results:&amp;nbsp;&lt;A href="http://pastebin.com/MS7Q1XEA" target="_blank"&gt;http://pastebin.com/MS7Q1XEA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Show version:&amp;nbsp;&lt;A href="http://pastebin.com/xe6RdhGc" target="_blank"&gt;http://pastebin.com/xe6RdhGc&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice or suggestions would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-cannot-access-some-https-websites/m-p/2686016#M193686</guid>
      <dc:creator>ben.yarwood</dc:creator>
      <dc:date>2019-03-12T06:17:05Z</dc:date>
    </item>
    <item>
      <title>Hi,I think the log shows the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-cannot-access-some-https-websites/m-p/2686017#M193688</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think the log shows the issue is on the server end that this is denying the connection from your internal hosts which you can see by all these RESET-O logs:-&lt;/P&gt;&lt;P&gt;6|Jul 17 2015|08:01:25|302014|204.193.144.91|443|10.200.200.2|52233|Teardown TCP connection 74078 for outside:204.193.144.91/443 to inside:10.200.200.2/52233 duration 0:00:00 bytes 266 TCP Reset-O&lt;/P&gt;&lt;P&gt;I think this might be something related to the SSL handshake between the server and the client.&lt;/P&gt;&lt;P&gt;You can apply captures on the ASA device interfaces and check the traces.&lt;/P&gt;&lt;P&gt;Also , as a test , what happens if you access the same servers from the clients which are dynamically natted on the ASA device ?&lt;/P&gt;&lt;P&gt;Also , you would recommend you to change this NAT as (any,any) is not recommended and it should have the name of the interface specifically :-&lt;/P&gt;&lt;P&gt;object network server&lt;BR /&gt;&amp;nbsp;nat (any,any) static 999.999.999.999&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2015 05:14:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-cannot-access-some-https-websites/m-p/2686017#M193688</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-07-18T05:14:35Z</dc:date>
    </item>
    <item>
      <title>Are you using ScanSafe or any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-cannot-access-some-https-websites/m-p/2686018#M193689</link>
      <description>&lt;P&gt;Are you using ScanSafe or any other type of URL filtering?&lt;/P&gt;&lt;P&gt;The TCP Reset-O flag indicates that the ASA is receiving the TCP-reset.&amp;nbsp; I agree with Vibhor that you should take a look at either the server or any URL filters if you are using any.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2015 06:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-cannot-access-some-https-websites/m-p/2686018#M193689</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-07-18T06:56:24Z</dc:date>
    </item>
  </channel>
</rss>

