<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I disable &amp;quot;inspect sqlnet?&amp;quot; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-i-disable-quot-inspect-sqlnet-quot/m-p/2334803#M310938</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can check the number of packets (if any) that matched that inspection:&lt;/P&gt;&lt;P&gt;show service-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Oct 2013 16:01:58 GMT</pubDate>
    <dc:creator>Patrick Moubarak</dc:creator>
    <dc:date>2013-10-15T16:01:58Z</dc:date>
    <item>
      <title>Can I disable "inspect sqlnet?"</title>
      <link>https://community.cisco.com/t5/network-security/can-i-disable-quot-inspect-sqlnet-quot/m-p/2334802#M310936</link>
      <description>&lt;P&gt;In a recent Cisco Security Advisory &lt;A href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131009-asa" target="_blank"&gt;(Advisory ID: cisco-sa-20131009-asa)&lt;/A&gt; there is a "SQL*Net Inspection Engine Denial of Service Vulnerability" identified.&amp;nbsp; I plan to follow the upgrade process to resolve this, however, I will not be able to perform the upgrade for a couple of weeks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The temporary work around suggested is to disable SQL*Net inspection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;ciscoasa(config)# policy-map global_policy
ciscoasa(config-pmap)# class inspection_default
ciscoasa(config-pmap-c)# no inspect sqlnet&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; This seems simple enough, but I am banging my head on the desk trying to figure out how this will affect any database traffic that may be going through these interfaces.&amp;nbsp; If the default sqlnet inspection is disabled does that mean I need to add explicit ACL entries per interface to allow that traffic?&amp;nbsp; I've reviewwed the information from this thread: &lt;A _jive_internal="true" href="https://community.cisco.com/thread/2005571" target="_blank"&gt;https://supportforums.cisco.com/thread/2005571&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there are SQL and Oracle databases on this particular segment, but what confuses me is that there are no rules configured to NAT anything right now.&amp;nbsp; Is there some sort of way to see if any traffic even matches that default inspection so I know whether it's doing anything right now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to be overthinking this because I keep going in circles with my own reasoning.&amp;nbsp; I'm not sure what config information to include with my question.&amp;nbsp; I can tell you that there are many interfaces in use.&amp;nbsp; There is no NAT.&amp;nbsp; There are mulitple security levels.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:52:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-disable-quot-inspect-sqlnet-quot/m-p/2334802#M310936</guid>
      <dc:creator>epatrickwhite</dc:creator>
      <dc:date>2019-03-12T02:52:10Z</dc:date>
    </item>
    <item>
      <title>Can I disable "inspect sqlnet?"</title>
      <link>https://community.cisco.com/t5/network-security/can-i-disable-quot-inspect-sqlnet-quot/m-p/2334803#M310938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can check the number of packets (if any) that matched that inspection:&lt;/P&gt;&lt;P&gt;show service-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 16:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-disable-quot-inspect-sqlnet-quot/m-p/2334803#M310938</guid>
      <dc:creator>Patrick Moubarak</dc:creator>
      <dc:date>2013-10-15T16:01:58Z</dc:date>
    </item>
    <item>
      <title>Can I disable "inspect sqlnet?"</title>
      <link>https://community.cisco.com/t5/network-security/can-i-disable-quot-inspect-sqlnet-quot/m-p/2334804#M310941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thank you!&lt;/STRONG&gt;&amp;nbsp; This was exactly what I was asking for.&amp;nbsp; In my post I asked the question "Is there some sort of way to see if any traffic even matches that default inspection."&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is all I needed.&amp;nbsp; I don't know why I couldn't find how to show this information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 18:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-disable-quot-inspect-sqlnet-quot/m-p/2334804#M310941</guid>
      <dc:creator>epatrickwhite</dc:creator>
      <dc:date>2013-10-15T18:52:21Z</dc:date>
    </item>
  </channel>
</rss>

