<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Jouni Forss , thanks for the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525413#M236054</link>
    <description>&lt;P&gt;&lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/jouniforss" title="View user profile."&gt;Jouni Forss&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="created"&gt;&lt;SPAN content="2014-07-31T12:56:42-07:00"&gt;&lt;SPAN class="timeago" title="Thu, 07/31/2014 - 12:56"&gt;, thanks for the posting, we lost link to syslog server, and the same thing happened.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging permit-hostdown &lt;/STRONG&gt;Worked great while we restore the link.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jan 2015 14:52:05 GMT</pubDate>
    <dc:creator>TomElkins3rd</dc:creator>
    <dc:date>2015-01-15T14:52:05Z</dc:date>
    <item>
      <title>ASA 5510 - Disallowing new connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525410#M236048</link>
      <description>&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;&lt;DIV class="field-items"&gt;&lt;DIV class="field-item even"&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm in need of some help here. We lost internet connection. I checked ASA syslog, I found that ASA was displaying disallowing new connections on the ASDM syslog:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Syslog ID: 201008: Disallowing new connections&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did a google search and didn't yield any good results. Any help would greatly be appreciated.&lt;/P&gt;&lt;P&gt;Need to know why and what caused this error, and what is the fix. Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525410#M236048</guid>
      <dc:creator>abcdefghi123</dc:creator>
      <dc:date>2019-03-12T04:33:41Z</dc:date>
    </item>
    <item>
      <title>Hi, I think we had this</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525411#M236050</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we had this problem when we enabled TCP based Syslog to a Syslog server (instead of the default UDP traffic). Unknown to us at that time was that if for any reason the Syslog server was not reached through that TCP connection the ASA would stop allowing new connections through it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then found out that to avoid this situation you had to have this command enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging permit-hostdown&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This command essentially allows the ASA to perform normally even if the Syslog server had become unreachable. Our problem in this case was related to misunderstanding on what the TCP port used should have been.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We added this command after the problem had started on a Security Context in a Multiple Context mode ASA and we found out also that adding this command later did not help with the situation. We went as far as removing all logging configurations and even the interface through which the Syslog server had been configured originally. None of this helped. In the end we had to remove the whole Security Context and enter it again in the System Context to get connections going through that particular Security Context.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I kind of wonder if you have configured TCP based Syslog messages on the ASA and the server has become unreachable and you dont have the above mentioned command enabled?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 19:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525411#M236050</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-07-31T19:56:42Z</dc:date>
    </item>
    <item>
      <title>Yes, TCP is enabled for</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525412#M236053</link>
      <description>&lt;P&gt;Yes, TCP is enabled for syslog server.&lt;/P&gt;&lt;P&gt;I have also enabled "Allow user traffic to pass when TCP syslog server is down". Hoping this will resolve the issue.&lt;/P&gt;&lt;P&gt;Will test the firewall again tomorrow evening to see if this solves the problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 21:56:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525412#M236053</guid>
      <dc:creator>abcdefghi123</dc:creator>
      <dc:date>2014-07-31T21:56:26Z</dc:date>
    </item>
    <item>
      <title>Jouni Forss , thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525413#M236054</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/jouniforss" title="View user profile."&gt;Jouni Forss&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="created"&gt;&lt;SPAN content="2014-07-31T12:56:42-07:00"&gt;&lt;SPAN class="timeago" title="Thu, 07/31/2014 - 12:56"&gt;, thanks for the posting, we lost link to syslog server, and the same thing happened.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging permit-hostdown &lt;/STRONG&gt;Worked great while we restore the link.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2015 14:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525413#M236054</guid>
      <dc:creator>TomElkins3rd</dc:creator>
      <dc:date>2015-01-15T14:52:05Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525414#M236055</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I know it's an older post, but it's still a problem &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If the command:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;logging permit-hostdown&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;not helps, you're hitting a bug which is not public. The bug is related to context firewalls.&lt;/P&gt;
&lt;P&gt;To fix the problem, the only solution is to re-create the context again. A reboot doesn't help.&lt;/P&gt;
&lt;P&gt;Here's a short instruction (repeat for every context):&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;remove tcp syslog server configuration&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;changeto contex XYZ&lt;BR /&gt;conf t&lt;BR /&gt;no logging host inside x.x.x.x tcp/xxx&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;save new configuration&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;changeto system&lt;BR /&gt;wr mem all&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;check configuration (optional)&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;more xyz.cfg | in logging&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;check context file:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;sh run context XYZ&lt;BR /&gt;context XYZ&lt;BR /&gt;&amp;lt;snip&amp;gt;&lt;BR /&gt; config-url disk0:/xyz.cfg&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;remove context configuration&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;changeto context XYZ&lt;BR /&gt;clear configure all&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Use context file again:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;changeto sys&lt;BR /&gt;context XYZ&lt;BR /&gt;conf t&lt;BR /&gt;config-url disk0:/xyz.cfg&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you have a failover pair, I recommend to remove the configuration of the secondary ASA and built up the failover cluster again.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards Andrin&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 16:27:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/2525414#M236055</guid>
      <dc:creator>arickenbach</dc:creator>
      <dc:date>2016-05-03T16:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Hi</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/5121381#M1113168</link>
      <description>&lt;P&gt;Thank you so very much, this was the fix for my issue with Cisco 5585 multi-context configuration ASA.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 20:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/5121381#M1113168</guid>
      <dc:creator>ferginator1</dc:creator>
      <dc:date>2024-05-30T20:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - Disallowing new connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/5161402#M1115101</link>
      <description>&lt;P&gt;10 Years later this post is still useful !&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 14:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-disallowing-new-connections/m-p/5161402#M1115101</guid>
      <dc:creator>Jerioux</dc:creator>
      <dc:date>2024-08-15T14:34:23Z</dc:date>
    </item>
  </channel>
</rss>

