<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The problem isn't going to be in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604502#M197610</link>
    <description>&lt;P&gt;The problem isn't going to be be a layer 1-4 issue since you establish the connection, but it drops sporadically. I would run a network capture on the firewall to see if the host is sending a reset. If that doesn't prove useful, I would run a capture on the nfs host and see if it's doing something strange like port hopping.&lt;/P&gt;&lt;P&gt;You will likely find your answer in the capture on the nfs host since you aren't likely hitting the conn timeouts in your config. SCP&amp;nbsp;has no RFC, so &amp;nbsp;the protocol implementations may vary depending on the library being used between devices.&lt;/P&gt;&lt;P&gt;I have run into issues with SCP between hosts that were caused by library bugs between hosts, so you may have ran into something similar.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jan 2015 19:24:32 GMT</pubDate>
    <dc:creator>united001</dc:creator>
    <dc:date>2015-01-27T19:24:32Z</dc:date>
    <item>
      <title>ASA Firewall Blocking SCP copy between the servers</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604499#M197607</link>
      <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;We are experiencing challenges related to &lt;SPAN style="color: black; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-ZA; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;SCP copy between the servers. I have reviewed the configurations applied on our Firewalls and I'm not able to detect any abnormalties on the configuration applied.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-ZA; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;I'm not sure if increasing the MTU size will make a difference. I have attached the output setting for our rules currently applied.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-ZA; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;#######################################################################################################&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;mtu OUTSIDE 1500&lt;BR /&gt;mtu INSIDE 1500&lt;BR /&gt;mtu Monitor-Port-Channel-104 1500&lt;BR /&gt;monitor-interface OUTSIDE&lt;BR /&gt;monitor-interface INSIDE&lt;BR /&gt;monitor-interface Monitor-Port-Channel-104&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;route OUTSIDE 0.0.0.0 0.0.0.0 10.15.2.129 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication enable console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 0.0.0.0 0.0.0.0 OUTSIDE&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 OUTSIDE&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;username admin password 76QP4zi7MB2mshOI encrypted&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;####################################################################################################################&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any assistance will be grately appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604499#M197607</guid>
      <dc:creator>ashvaldo</dc:creator>
      <dc:date>2019-03-12T05:23:44Z</dc:date>
    </item>
    <item>
      <title>Do you have basic</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604500#M197608</link>
      <description>&lt;P&gt;Do you have basic connectivity between the servers (ie. ping between the servers)? Just remember to disable windows firewall or any other locally installed firewall when testing with ping.&lt;/P&gt;&lt;P&gt;Have you run a packet tracer to see if the SCP packet is allowed through the firewall? &amp;nbsp;By default SCP uses port TCP 22.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input &amp;lt;ingress interface&amp;gt; tcp &amp;lt;source IP&amp;gt; 12345 &amp;lt;destination IP&amp;gt; 22 detailed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2015 09:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604500#M197608</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-01-26T09:43:29Z</dc:date>
    </item>
    <item>
      <title>Good day Marius, The host are</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604501#M197609</link>
      <description>&lt;P&gt;Good day Marius,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The host are able to ping and connect to each other vai telnet. The concern is when we try to do the SCP connection when it fails. The host are IBM p570 and the connectivity problem exist when performing and NFS mount. The connection is established and after a short while the connection is lost resulting in the ORACLE Database hanging.&lt;/P&gt;&lt;P&gt;The only device between the host are the CISCO ASA Firewalls and TIPPINGPOINT. We have checked&amp;nbsp;both ASA and TIPPINGPOINT devices and the result remain unchanged.&lt;/P&gt;&lt;P&gt;Thanks so much the feedback received thus far.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2015 12:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604501#M197609</guid>
      <dc:creator>ashvaldo</dc:creator>
      <dc:date>2015-01-26T12:29:31Z</dc:date>
    </item>
    <item>
      <title>The problem isn't going to be</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604502#M197610</link>
      <description>&lt;P&gt;The problem isn't going to be be a layer 1-4 issue since you establish the connection, but it drops sporadically. I would run a network capture on the firewall to see if the host is sending a reset. If that doesn't prove useful, I would run a capture on the nfs host and see if it's doing something strange like port hopping.&lt;/P&gt;&lt;P&gt;You will likely find your answer in the capture on the nfs host since you aren't likely hitting the conn timeouts in your config. SCP&amp;nbsp;has no RFC, so &amp;nbsp;the protocol implementations may vary depending on the library being used between devices.&lt;/P&gt;&lt;P&gt;I have run into issues with SCP between hosts that were caused by library bugs between hosts, so you may have ran into something similar.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 19:24:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-blocking-scp-copy-between-the-servers/m-p/2604502#M197610</guid>
      <dc:creator>united001</dc:creator>
      <dc:date>2015-01-27T19:24:32Z</dc:date>
    </item>
  </channel>
</rss>

