<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5580 local-host problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5580-local-host-problem/m-p/2520755#M234993</link>
    <description>&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/drawing1_11.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;We have 2 border routers (7609-S) running BGP routing protocol with 3 different ISPs and are connecting to 2 ASA5580-40 firewalls (Active-standby mode).&lt;/P&gt;&lt;P&gt;A server X on Interent is connecting to our server Y in LAN. Server X is unable to connect to server Y if any of the 3 ISP links got interrupted. Even link is recovered but X still failed to connection to Y everytime.&lt;/P&gt;&lt;P&gt;We found that didn't find any IPINIP connection when I do " show local-host x.x.x.x(IP of X) on ASA firewall:&lt;/P&gt;&lt;P&gt;(IP of X &amp;amp; Y are shown as x.x.x.x and y.y.y.y for confidentiality)&lt;/P&gt;&lt;P&gt;FW01# sh local-host x.x.x.x&lt;BR /&gt;Interface Inside: 1554344 active, 1610150 maximum active, 0 denied&lt;BR /&gt;Interface Outside: 1040329 active, 1465152 maximum active, 0 denied&lt;BR /&gt;local host: &amp;lt;x.x.x.x&amp;gt;,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 0/unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP Outside x.x.x.x:434 Outside y.y.y.y:434, idle 0:00:00, bytes 3310318788, flags -&lt;BR /&gt;Interface Stateful: 1 active, 2 maximum active, 0 denied&lt;BR /&gt;Interface management: 1 active, 4 maximum active, 0 denied&lt;BR /&gt;Interface Failover: 1 active, 2 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Once I issue "clear local-host x.x.x.x", the connection is up:&lt;/P&gt;&lt;P&gt;FW01# clear local-host x.x.x.x&lt;BR /&gt;FW01# sh local-host x.x.x.x &amp;nbsp;&lt;BR /&gt;Interface Inside: 1554451 active, 1610150 maximum active, 0 denied&lt;BR /&gt;Interface Outside: 1039506 active, 1465152 maximum active, 0 denied&lt;BR /&gt;local host: &amp;lt;x.x.x.x&amp;gt;,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 0/unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPINIP Outside x.x.x.x Inside y.y.y.y, idle 0:00:00, bytes 3440&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP Outside x.x.x.x:434 Inside y.y.y.y:434, idle 0:00:00, bytes 2156, flags -&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPINIP Outside x.x.x.x Inside y.y.y.y, idle 0:00:00, bytes 2784&lt;BR /&gt;Interface Stateful: 1 active, 2 maximum active, 0 denied&lt;BR /&gt;Interface management: 1 active, 4 maximum active, 0 denied&lt;BR /&gt;Interface Failover: 1 active, 2 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We have workaround to do clear local-host everytime now but are still finding solution on it. Could anyone adivce on it please? thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:43:46 GMT</pubDate>
    <dc:creator>Leo Liu</dc:creator>
    <dc:date>2019-03-12T04:43:46Z</dc:date>
    <item>
      <title>ASA 5580 local-host problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-local-host-problem/m-p/2520755#M234993</link>
      <description>&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/drawing1_11.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;We have 2 border routers (7609-S) running BGP routing protocol with 3 different ISPs and are connecting to 2 ASA5580-40 firewalls (Active-standby mode).&lt;/P&gt;&lt;P&gt;A server X on Interent is connecting to our server Y in LAN. Server X is unable to connect to server Y if any of the 3 ISP links got interrupted. Even link is recovered but X still failed to connection to Y everytime.&lt;/P&gt;&lt;P&gt;We found that didn't find any IPINIP connection when I do " show local-host x.x.x.x(IP of X) on ASA firewall:&lt;/P&gt;&lt;P&gt;(IP of X &amp;amp; Y are shown as x.x.x.x and y.y.y.y for confidentiality)&lt;/P&gt;&lt;P&gt;FW01# sh local-host x.x.x.x&lt;BR /&gt;Interface Inside: 1554344 active, 1610150 maximum active, 0 denied&lt;BR /&gt;Interface Outside: 1040329 active, 1465152 maximum active, 0 denied&lt;BR /&gt;local host: &amp;lt;x.x.x.x&amp;gt;,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 0/unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP Outside x.x.x.x:434 Outside y.y.y.y:434, idle 0:00:00, bytes 3310318788, flags -&lt;BR /&gt;Interface Stateful: 1 active, 2 maximum active, 0 denied&lt;BR /&gt;Interface management: 1 active, 4 maximum active, 0 denied&lt;BR /&gt;Interface Failover: 1 active, 2 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Once I issue "clear local-host x.x.x.x", the connection is up:&lt;/P&gt;&lt;P&gt;FW01# clear local-host x.x.x.x&lt;BR /&gt;FW01# sh local-host x.x.x.x &amp;nbsp;&lt;BR /&gt;Interface Inside: 1554451 active, 1610150 maximum active, 0 denied&lt;BR /&gt;Interface Outside: 1039506 active, 1465152 maximum active, 0 denied&lt;BR /&gt;local host: &amp;lt;x.x.x.x&amp;gt;,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 0/unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPINIP Outside x.x.x.x Inside y.y.y.y, idle 0:00:00, bytes 3440&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP Outside x.x.x.x:434 Inside y.y.y.y:434, idle 0:00:00, bytes 2156, flags -&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPINIP Outside x.x.x.x Inside y.y.y.y, idle 0:00:00, bytes 2784&lt;BR /&gt;Interface Stateful: 1 active, 2 maximum active, 0 denied&lt;BR /&gt;Interface management: 1 active, 4 maximum active, 0 denied&lt;BR /&gt;Interface Failover: 1 active, 2 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We have workaround to do clear local-host everytime now but are still finding solution on it. Could anyone adivce on it please? thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-local-host-problem/m-p/2520755#M234993</guid>
      <dc:creator>Leo Liu</dc:creator>
      <dc:date>2019-03-12T04:43:46Z</dc:date>
    </item>
    <item>
      <title>Hello; This specifies UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-local-host-problem/m-p/2520756#M234994</link>
      <description>&lt;P&gt;Hello;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This specifies UDP (typo on the document or whatever) but you can use the "timeout-floating-conn".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113592-udp-traffic-fails-00.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will kill the connection that is floating on an non existing interface instead of waiting for the whole hour or to manually clear the conn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2014 00:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-local-host-problem/m-p/2520756#M234994</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2014-09-16T00:40:17Z</dc:date>
    </item>
  </channel>
</rss>

