<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA drop upload session in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-drop-upload-session/m-p/2371185#M271265</link>
    <description>&lt;P&gt;Hi, I have asa with policy map below when ever anybody wants to upload large file it drops after some time, since i have multiple services i exclude ip of upload server from access-list and then evrything works normally i want to add and fine tune the below policy map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;tcp-map tcp-NORM_Map&lt;BR /&gt;&amp;nbsp; check-retransmission &lt;BR /&gt;&amp;nbsp; checksum-verification &lt;BR /&gt;&amp;nbsp; exceed-mss drop&lt;BR /&gt;&amp;nbsp; queue-limit 5 timeout 3&lt;BR /&gt;&amp;nbsp; syn-data drop&lt;BR /&gt;&amp;nbsp; window-variation drop-connection&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;policy-map CONNS_policy&lt;BR /&gt;class CONNS_Class&lt;BR /&gt;&amp;nbsp; set connection conn-max 1500 embryonic-conn-max 200 per-client-max 10 per-client-embryonic-max 15 &lt;BR /&gt;&amp;nbsp; set connection timeout embryonic 0:00:45 half-closed 0:05:00 tcp 0:10:00 reset dcd 0:00:20 3 &lt;BR /&gt;&amp;nbsp; set connection advanced-options tcp-NORM_Map&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:32:12 GMT</pubDate>
    <dc:creator>alkabeer80</dc:creator>
    <dc:date>2019-03-12T03:32:12Z</dc:date>
    <item>
      <title>ASA drop upload session</title>
      <link>https://community.cisco.com/t5/network-security/asa-drop-upload-session/m-p/2371185#M271265</link>
      <description>&lt;P&gt;Hi, I have asa with policy map below when ever anybody wants to upload large file it drops after some time, since i have multiple services i exclude ip of upload server from access-list and then evrything works normally i want to add and fine tune the below policy map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;tcp-map tcp-NORM_Map&lt;BR /&gt;&amp;nbsp; check-retransmission &lt;BR /&gt;&amp;nbsp; checksum-verification &lt;BR /&gt;&amp;nbsp; exceed-mss drop&lt;BR /&gt;&amp;nbsp; queue-limit 5 timeout 3&lt;BR /&gt;&amp;nbsp; syn-data drop&lt;BR /&gt;&amp;nbsp; window-variation drop-connection&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;policy-map CONNS_policy&lt;BR /&gt;class CONNS_Class&lt;BR /&gt;&amp;nbsp; set connection conn-max 1500 embryonic-conn-max 200 per-client-max 10 per-client-embryonic-max 15 &lt;BR /&gt;&amp;nbsp; set connection timeout embryonic 0:00:45 half-closed 0:05:00 tcp 0:10:00 reset dcd 0:00:20 3 &lt;BR /&gt;&amp;nbsp; set connection advanced-options tcp-NORM_Map&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:32:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-drop-upload-session/m-p/2371185#M271265</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2019-03-12T03:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA drop upload session</title>
      <link>https://community.cisco.com/t5/network-security/asa-drop-upload-session/m-p/2371186#M271266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you gathered any firewalls logs or traffic capture data from the dropped connections?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure that the TCP Map setting of &lt;STRONG&gt;"window-variation drop-connection"&lt;/STRONG&gt; is not doing this to your connections? If this setting simply refers to a situation where the window size is changed and because of that dropped I would imagine large transfers will get dropped as I imagine the window size changed during the transfer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the command&lt;STRONG&gt; "show service-policy"&lt;/STRONG&gt; provide any information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jan 2014 10:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-drop-upload-session/m-p/2371186#M271266</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-01-20T10:20:12Z</dc:date>
    </item>
  </channel>
</rss>

