<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic this version is affected by in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668058#M195250</link>
    <description>&lt;P&gt;this version is affected by the DOS. As a TAC engineer I don't see device reloading 99% time. The condition says it "may" reload.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please upgrade to 9.1.3 or 9.1.5 and see if it fixes the issue.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2015 16:05:15 GMT</pubDate>
    <dc:creator>Pranay Prasoon</dc:creator>
    <dc:date>2015-04-08T16:05:15Z</dc:date>
    <item>
      <title>Teardown TCP connection - Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668053#M195242</link>
      <description>&lt;P&gt;Good Morning.&lt;/P&gt;&lt;P&gt;I've a great problem with my new ASA 5515-X Configured in Active/Standby Failover.&lt;/P&gt;&lt;P&gt;This is a company that have 8 remote branches connected via VPN Site-to-Site with our ASAs on the main site. All the remote branches have one or two ASA (configured in Failover Active/Standby too in this case). Normal VPN traffic works fine and also the Internet connections. Problems arrive when an host starts to upload (or download) a medium sized file toward an branch office via SMB protocol, or when some database start to upload other databases in the central office. at random, the connection between hosts reset and the download/upload it stop without finish.&lt;/P&gt;&lt;P&gt;Debugging the ASA I saw that this message is producted:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2015-04-08 14:09:31&amp;nbsp;&amp;nbsp; &amp;nbsp;Local4.Info&amp;nbsp;&amp;nbsp; &amp;nbsp;131.1.55.55&amp;nbsp;&amp;nbsp; &amp;nbsp;:Apr 08 14:09:37 CEST: %ASA-session-6-302014: Teardown TCP connection 28477562 for outside:192.168.13.245/445 to inside:131.1.60.60/6962 duration 0:57:02 bytes 2206518128 Flow closed by inspection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the default inspection configured on ASA, and there's not others inspection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect waas&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really don't know how to fix this great problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668053#M195242</guid>
      <dc:creator>Luigi Celeste</dc:creator>
      <dc:date>2019-03-12T05:44:54Z</dc:date>
    </item>
    <item>
      <title>Good day. For testing</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668054#M195243</link>
      <description>&lt;P&gt;Good day. For testing purposes,&amp;nbsp;Can you try to remove NetBIOS from your inspection policy map?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 14:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668054#M195243</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-04-08T14:56:47Z</dc:date>
    </item>
    <item>
      <title>There is nothing like SMB</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668055#M195245</link>
      <description>&lt;P&gt;There is nothing like SMB inspection on ASA.&lt;/P&gt;&lt;P&gt;I just have&amp;nbsp; a gut feeling it is ICMP denial of service on ASA. Can you please tell your ASA software version?&lt;/P&gt;&lt;P&gt;https://tools.cisco.com/bugsearch/bug/CSCui77398/?reffering_site=dumpcr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 15:26:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668055#M195245</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2015-04-08T15:26:55Z</dc:date>
    </item>
    <item>
      <title>Thank's for the reply first</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668056#M195247</link>
      <description>&lt;P&gt;Thank's for the reply first!&lt;/P&gt;&lt;P&gt;The ASA Version is 9.1(2)&lt;/P&gt;&lt;P&gt;But reading the bug features, my ASA does not reload itself, but only Teardown the connection who downloading/uploading a large file, or attempting to do download/upload from a few minutes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 15:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668056#M195247</guid>
      <dc:creator>Luigi Celeste</dc:creator>
      <dc:date>2015-04-08T15:56:50Z</dc:date>
    </item>
    <item>
      <title>Thank's for reply!Sure, i</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668057#M195248</link>
      <description>&lt;P&gt;Thank's for reply!&lt;/P&gt;&lt;P&gt;Sure, i could, but&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt; which&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;do you think is&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the behavior&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;that causes this&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;error&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;leaving&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;enabled&lt;/SPAN&gt;&lt;/SPAN&gt; NetBios inspection?&lt;/P&gt;&lt;P&gt;Also, this ASA is replacing an Old ASA 5510 (ASA Version 7.0(8) ) that in its configuration had enabled the default NetBios inspection too and everything works without problems like now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I followed also the advice of enable the commands:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sysopt connection preserve-vpn-flows &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sysopt connection reclassify-vpn&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(https://supportforums.cisco.com/discussion/11860166/asa5585-ssp-20-912-flow-closed-inspection)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in the same way I continue to have problems when downloding or uploading large files toward VPN site-to-site connections. Really don't know how to solve this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate really your interest. Thank's for what you can do to solve this problem!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 16:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668057#M195248</guid>
      <dc:creator>Luigi Celeste</dc:creator>
      <dc:date>2015-04-08T16:04:32Z</dc:date>
    </item>
    <item>
      <title>this version is affected by</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668058#M195250</link>
      <description>&lt;P&gt;this version is affected by the DOS. As a TAC engineer I don't see device reloading 99% time. The condition says it "may" reload.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please upgrade to 9.1.3 or 9.1.5 and see if it fixes the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 16:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668058#M195250</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2015-04-08T16:05:15Z</dc:date>
    </item>
    <item>
      <title>I have the possibility to</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668059#M195251</link>
      <description>&lt;P&gt;I have the possibility to upgrade my ASA at the Version 9.2(2), I can download the OS from an ASA of a remote branch. Do you think this may fix my problems?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 16:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668059#M195251</guid>
      <dc:creator>Luigi Celeste</dc:creator>
      <dc:date>2015-04-08T16:08:38Z</dc:date>
    </item>
    <item>
      <title>Yes 9.2.2 is clean. Please</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668060#M195252</link>
      <description>&lt;P&gt;Yes 9.2.2 is clean. Please upgrade and let me know the result.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 16:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668060#M195252</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2015-04-08T16:16:27Z</dc:date>
    </item>
    <item>
      <title>Great news! Tomorrow will be</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668061#M195253</link>
      <description>&lt;P&gt;Great news! Tomorrow will be the first thing I'll do at work. After some testing I'll let you know immediately! Hope it will works!&lt;/P&gt;&lt;P&gt;Thank's for now!&lt;/P&gt;&lt;P&gt;Luigi Celeste&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 21:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668061#M195253</guid>
      <dc:creator>Luigi Celeste</dc:creator>
      <dc:date>2015-04-08T21:01:14Z</dc:date>
    </item>
    <item>
      <title>Hi Pranay Prasoon,2 days ago</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668062#M195254</link>
      <description>&lt;P&gt;Hi Pranay Prasoon,&lt;/P&gt;&lt;P&gt;2 days ago i've upgraded my ASA Version to the 9.2(2) in Italy and then I start a lot of testing downloading and uploading some giga of files from and to the ours remote sites. Well, I can definitely say that everything went OK!!! files are correctly transferred, VPN connection from sites never tear down!&lt;/P&gt;&lt;P&gt;Also, there was the problem that when VPN connections were tearing down for some seconds (5-6 seconds in average), also IPSLA&amp;nbsp;(that is configured with a primary provider and a backup provider) immediately trigger and for 5-6 seconds uses the second provider, after which&amp;nbsp;to come back to use the first provider. Also this correlated problem seems disappeared.&lt;/P&gt;&lt;P&gt;Monday I've to reconnect yet&amp;nbsp;also the secondary ASA as Standby failover (because I didn't have changed yet the OS version in waiting for testing), and see if failover trigger itself for no apparent reason (&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;that&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;was&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;another anomaly&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;that occurred). When all it's tested for at least&amp;nbsp;one week I can definitely say that the problem is totally solved, but&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;in principle&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;it's &lt;/SPAN&gt;&lt;SPAN class="hps"&gt;already!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Then I would to really thank you for this great support that seems to have solved a lot of network problem related to this bug!!!&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Luigi Celeste&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV id="gt-input-tool" style="display: inline-block;"&gt;&lt;DIV id="itamenu"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="g-unit" id="gt-src-c"&gt;&lt;DIV id="gt-src-p"&gt;&lt;DIV id="gt-src-wrap"&gt;&lt;DIV id="gt-src-tools"&gt;&lt;DIV id="gt-src-tools-r"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 11 Apr 2015 19:27:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-flow-closed-by-inspection/m-p/2668062#M195254</guid>
      <dc:creator>Luigi Celeste</dc:creator>
      <dc:date>2015-04-11T19:27:57Z</dc:date>
    </item>
  </channel>
</rss>

