<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 FireWall Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338029#M310913</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you confirmed that the &lt;STRONG&gt;"logging"&lt;/STRONG&gt; settings are at appropriate level to see the connection building and teardown messages? The default level for those is &lt;STRONG&gt;"informational"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see the current logging settings with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run logging&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you should be able to see something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally you could even go as far to capture traffic on the ASA to give definitive answer on if traffic is reaching ASA and if it is, what traffic is actually passed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Oct 2013 15:14:15 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-10-15T15:14:15Z</dc:date>
    <item>
      <title>ASA 5510 FireWall Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338024#M310908</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;After some advise and direction&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our ASA firewall using ASA version 8.4 has recently started presenting us with a problem to one external website&lt;/P&gt;&lt;P&gt;called &lt;A href="http://partners.highnet.com/login/" target="_blank"&gt;http://partners.highnet.com/login/&lt;/A&gt;&amp;nbsp; ip address 62.233.82.181.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our firewall is letting everything on our inside Trusted site 192.168.254.0/24 out through our outside interface on x.x.x.x&lt;/P&gt;&lt;P&gt;to any website and brings back the details&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However when we try to reach &lt;A href="http://partners.highnet.com/login/" target="_blank"&gt;http://partners.highnet.com/login/&lt;/A&gt; we recently started receiving (Internet Explorer cannot display the webpage)&lt;/P&gt;&lt;P&gt;on checking the ASA under Home TAB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Firewall Dashboard&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp; and then under&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Top 10 protected Servers under SYN attack we are receiving the below error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rank&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server IP-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Average&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source IP (Last Attack Time)&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" style="padding: px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P&gt;5&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62.233.82.181:80&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INSIDE&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.254.130 (1 mins ago) &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried rebooting the ASA firewall (Still did not resolve).&lt;/P&gt;&lt;P&gt;I have also&amp;nbsp; disabled basic threat detection and threat detection statistics and then re-enabled after a period of time under &amp;gt; configuration &amp;gt; Firewall &amp;gt; threat detection&amp;nbsp; (Still did not resolve).&lt;/P&gt;&lt;P&gt;Have created a number of access list both from the inside to outside and outside to inside allowing TCP just to the specific IP address 62.233.82.181 (Still did not resolve).&lt;/P&gt;&lt;P&gt;Tried editing Global Policy for Http configuration &amp;gt; connection settings TCP and UDP connections and also Embryonic connections (Still did not resolve).&lt;/P&gt;&lt;P&gt;Also tried using the shun command on the ASA to clear connection and statistics and (Still did not resolve).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you see there is nothing else I can think of doing, so that is why I have asked you for some pointers maybe someone has come across this sort of issue before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can help or advise it is much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338024#M310908</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2019-03-12T02:52:15Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 FireWall Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338025#M310909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sending logs from your ASA to any Syslog server from which you could pull all the connection logs for that destination IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA you can naturally use &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; also to simulate one such packet coming from your LAN towards this WAN IP address (of the server) and confirm that all rules are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input INSIDE tcp 192.168.254.130 12345 62.233.82.181 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could maybe also try to generate TCP SYNs directly from the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ping tcp 62.233.82.181 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And see if the server replies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 11:55:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338025#M310909</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-15T11:55:05Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 FireWall Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338026#M310910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On using Packet tracer going from our inside to outside as you have mentioned shows clearly&lt;/P&gt;&lt;P&gt;that this is allowed to pass through the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have also run pings to 62.232.82.181 from the ASA no replies this also happens from an external site so I beleive&lt;/P&gt;&lt;P&gt;pings are turned off at the destination ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The stange thing is anybody from outside our internal network can get to this site is just seems to be our internal network set on the inside interface of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;REgards&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 12:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338026#M310910</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2013-10-15T12:09:13Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 FireWall Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338027#M310911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you have the &lt;STRONG&gt;"inspect http"&lt;/STRONG&gt; enabled during this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can confirm this currently with &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run policy-map&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you could try removing it if its not needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would still also check the log messages while the connection attempt is going from a internal host. It should tell if the connections goes through and if the remote end replys to the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am behind an ASA and can get to that site just fine. At home I can test that site even from a device thats running the same software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 12:56:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338027#M310911</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-15T12:56:49Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 FireWall Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338028#M310912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yep I have had the "&lt;STRONG&gt;inspect http" &lt;/STRONG&gt;turned both on and off through the global policy still did not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have also checked the ASA log and can see no entry going to the ip address mentioned either stopping or blocking&lt;/P&gt;&lt;P&gt;the packets going out the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 13:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338028#M310912</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2013-10-15T13:37:53Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 FireWall Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338029#M310913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you confirmed that the &lt;STRONG&gt;"logging"&lt;/STRONG&gt; settings are at appropriate level to see the connection building and teardown messages? The default level for those is &lt;STRONG&gt;"informational"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see the current logging settings with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run logging&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you should be able to see something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally you could even go as far to capture traffic on the ASA to give definitive answer on if traffic is reaching ASA and if it is, what traffic is actually passed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 15:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338029#M310913</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-15T15:14:15Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 FireWall Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338030#M310914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logging is set for debugging and I can see a lot of entries captured from a number of diffrent&lt;/P&gt;&lt;P&gt;source and destination ip addresses, however when I run internet explorer from my machine&lt;/P&gt;&lt;P&gt;I am expecting to see my IP address attempting to reach destination&amp;nbsp; 62.232.82.181 but I can see nothing at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 15:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338030#M310914</guid>
      <dc:creator>Highnet_TSC</dc:creator>
      <dc:date>2013-10-15T15:31:34Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 FireWall Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338031#M310915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I would probably attempt the connection from multiple hosts and check every L3 device routing table in between host and the ASA so that you can confirm that the traffic is not being routed somewhere else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I dont know your environment I am not sure if this is a possibility.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you can't see any connection on the ASA then either the host is not connecting to that host or the traffic is not forwarded all the way to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a chance of a DNS related problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does ICMP to the destination IP address and/or DNS name arrive on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 15:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-firewall-problem/m-p/2338031#M310915</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-15T15:37:02Z</dc:date>
    </item>
  </channel>
</rss>

