<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic That's the command I can in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682634#M193736</link>
    <description>&lt;P&gt;That's the command I can never remember.&amp;nbsp; It appears that it is not being dropped, as it is coming up empty.&amp;nbsp;&amp;nbsp; I opened a TAC case on this as we believe the ASA is redirecting it, but its being lost in the ether(net).&amp;nbsp; The fact we are not seeing a return from the outside server means that is either not being translated, or is being redirected to the Ironports, which are ignoring them.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2015 12:54:14 GMT</pubDate>
    <dc:creator>tahscolony</dc:creator>
    <dc:date>2015-07-17T12:54:14Z</dc:date>
    <item>
      <title>AWS Workspaces port 4172 through ASA 8.2</title>
      <link>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682632#M193729</link>
      <description>&lt;P&gt;OK, this one has me stumped.&amp;nbsp; Trying to connect the client to work spaces, it needs access to port 4172 for TCP and UDP.&amp;nbsp; I have the Inside ACL allowing access to 4172, I see hits, I see the packet come in, but thats it.&amp;nbsp; I can't see if it is translating.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, if I switch to the guest network, which runs through a different firewall on 8.4 code, it works just fine. The problem appears to be the firewall, and I can't seem to find the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a capture showing the packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;56: 15:49:55.403467 192.168.43.24.51751 &amp;gt; 54.173.124.226.4172: S 913847066:913847066(0) win 8192 &amp;lt;mss 1260,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;BR /&gt;&amp;nbsp; 57: 15:49:56.417474 192.168.43.24.51752 &amp;gt; 54.173.124.226.4172: S 2446962769:2446962769(0) win 8192 &amp;lt;mss 1260,nop,wscale 8,nop,nop,sackOK&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what I see on the working ASA.&lt;/P&gt;&lt;P&gt;6|Jul 16 2015|14:51:57|302013|10.111.100.175|65522|54.173.124.226|4172|Built outbound TCP connection 188022257 for outside:54.173.124.226/4172 (54.173.124.226/4172) to dmz_guest:10.111.100.175/65522&lt;/P&gt;&lt;P&gt;Here is another puzzling thing, in ASDM logging, which is where the above came from, on the other ASA I do not see any 4172 transactions, I only see them when I do a CLI capture. I also do not see them when I do a packet capture wizard through ASDM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a WSA, but my IP bypasses it completely and a grep on both WSA shows no transactions from my PC.&amp;nbsp; It is as though it is not translating 4172.&amp;nbsp; A show xlate local for my IP does not show any xlate for 4172.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682632#M193729</guid>
      <dc:creator>tahscolony</dc:creator>
      <dc:date>2019-03-12T06:16:40Z</dc:date>
    </item>
    <item>
      <title>Hi, Could you provide the</title>
      <link>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682633#M193733</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you provide the output of "show asp drop | in 54.173.124.226" if the packet would be dropped by the firewall it would come under asp drops.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prateek Verma&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 06:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682633#M193733</guid>
      <dc:creator>prateek.verma</dc:creator>
      <dc:date>2015-07-17T06:08:46Z</dc:date>
    </item>
    <item>
      <title>That's the command I can</title>
      <link>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682634#M193736</link>
      <description>&lt;P&gt;That's the command I can never remember.&amp;nbsp; It appears that it is not being dropped, as it is coming up empty.&amp;nbsp;&amp;nbsp; I opened a TAC case on this as we believe the ASA is redirecting it, but its being lost in the ether(net).&amp;nbsp; The fact we are not seeing a return from the outside server means that is either not being translated, or is being redirected to the Ironports, which are ignoring them.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 12:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682634#M193736</guid>
      <dc:creator>tahscolony</dc:creator>
      <dc:date>2015-07-17T12:54:14Z</dc:date>
    </item>
    <item>
      <title>OK I discovered why its not</title>
      <link>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682635#M193738</link>
      <description>&lt;P&gt;OK I discovered why its not translating the port. Back about a month ago, prior to testing, we decided to redirect the port to WSA, then use transparent redirection, which turned out to not be the proper method, and so removed 4172 from the redirect ACL.&amp;nbsp; However, the service for the redirection has latched onto the port and wont release it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;WCCP service information definition:&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dynamic&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Id:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Priority:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 240&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Protocol:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Options:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000012&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;--------&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hash:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DstIP&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alt Hash:&amp;nbsp; -none-&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination:: &lt;STRONG&gt;4172&lt;/STRONG&gt; 8080 0 0 0 0 0 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this is why its not working, but now have to find out how to remove the port without rebooting the ASA or disrupting traffic in any way.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 14:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aws-workspaces-port-4172-through-asa-8-2/m-p/2682635#M193738</guid>
      <dc:creator>tahscolony</dc:creator>
      <dc:date>2015-07-17T14:53:38Z</dc:date>
    </item>
  </channel>
</rss>

