<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic http inspect in ASA 5510 messes up svn authentication in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/http-inspect-in-asa-5510-messes-up-svn-authentication/m-p/2231519#M349940</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; See here on how the inspect actually works (for version 8.2) and maybe you find the reason why it gets blocked:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i2.html#wp1735782"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i2.html#wp1735782&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 May 2013 14:10:40 GMT</pubDate>
    <dc:creator>patoberli</dc:creator>
    <dc:date>2013-05-15T14:10:40Z</dc:date>
    <item>
      <title>http inspect in ASA 5510 messes up svn authentication</title>
      <link>https://community.cisco.com/t5/network-security/http-inspect-in-asa-5510-messes-up-svn-authentication/m-p/2231518#M349939</link>
      <description>&lt;P&gt;I have a strange problem in my ASA 5510 firewall. I turned on http inspect policy to block certain URLs, but that destroyed svn communication. Interestingly, if I use simple web-browser to access svn server - it works, but any svn-client requests fail with an error "Could not read status line: An existing connection was forcibly closed by the remote host". I did some packet sniffing, and discovered that with http inspect off the WebDAV request is answered, but with http inspect on it is rejected with an error unauthorized. Here are examples of success and failed conversation packets:&lt;/P&gt;&lt;P&gt;Success:&lt;/P&gt;&lt;P&gt;1. &amp;lt;Client-IP&amp;gt; &amp;lt;Server-IP&amp;gt; WEBDAV WEBDAV:Request, PROPFIND /svn/repos/myrepo/trunk&amp;nbsp; {HTTP:3, TCP:2, IPv4:1}&lt;/P&gt;&lt;P&gt;2. &amp;lt;Client-IP&amp;gt; &amp;lt;Server-IP&amp;gt; WEBDAV WEBDAV:HTTP Payload, URL: /svn/repos/myrepo/trunk&amp;nbsp; {HTTP:3, TCP:2, IPv4:1}&lt;/P&gt;&lt;P&gt;3. &amp;lt;Server-IP&amp;gt; &amp;lt;Client-IP&amp;gt; TCP TCP:Flags=...A...., SrcPort=HTTP(80), DstPort=58882, PayloadLen=0, Seq=4139355337, Ack=3464798063, Win=258 (scale factor 0x8) = 66048 {TCP:2, IPv4:1}&lt;/P&gt;&lt;P&gt;4. &amp;lt;Server-IP&amp;gt; &amp;lt;Client-IP&amp;gt; WEBDAV WEBDAV:Response, HTTP/1.1, Status: UNHANDLED HTTP Status Code, URL: /svn/repos/myrepo/trunk&amp;nbsp; {HTTP:3, TCP:2, IPv4:1}&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Failure:&lt;/P&gt;&lt;P&gt;1. &amp;lt;Client-IP&amp;gt; &amp;lt;Server-IP&amp;gt; WEBDAV WEBDAV:Request, PROPFIND /svn/repos/myrepo/trunk {HTTP:3, TCP:2, IPv4:1}&lt;/P&gt;&lt;P&gt;2. &amp;lt;Client-IP&amp;gt; &amp;lt;Server-IP&amp;gt; WEBDAV WEBDAV:HTTP Payload, URL: /svn/repos/myrepo/trunk {HTTP:3, TCP:2, IPv4:1}&lt;/P&gt;&lt;P&gt;3. &amp;lt;Server-IP&amp;gt; &amp;lt;Client-IP&amp;gt; TCP TCP:Flags=...A.R.., SrcPort=HTTP(80), DstPort=1137, PayloadLen=0, Seq=1075661931, Ack=4049054406, Win=64240 (scale factor 0x0) = 64240 {TCP:2, IPv4:1}&lt;/P&gt;&lt;P&gt;4. &amp;lt;Client-IP&amp;gt; &amp;lt;Server-IP&amp;gt; TCP TCP:Flags=......S., SrcPort=1138, DstPort=HTTP(80), PayloadLen=0, Seq=1032908784, Ack=0, Win=64240 ( ) = 64240 {TCP:4, IPv4:1}&lt;/P&gt;&lt;P&gt;5. &amp;lt;Server-IP&amp;gt; &amp;lt;Client-IP&amp;gt; TCP TCP:Flags=...A..S., SrcPort=HTTP(80), DstPort=1138, PayloadLen=0, Seq=4184445498, Ack=1032908785, Win=8192 ( Scale factor not supported ) = 8192 {TCP:4, IPv4:1}&lt;/P&gt;&lt;P&gt;6. &amp;lt;Client-IP&amp;gt; &amp;lt;Server-IP&amp;gt; TCP TCP:Flags=...A...., SrcPort=1138, DstPort=HTTP(80), PayloadLen=0, Seq=1032908785, Ack=4184445499, Win=64240 (scale factor 0x0) = 64240 {TCP:4, IPv4:1}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Packet # 4 is an actual differentiator.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Does anybody had that issue or know the solution?&lt;/P&gt;&lt;P&gt;I found one mentioning of that error with that assessment: "Older firewall/proxies do not understand the WebDAV related HTTP requests for accessing Subversion using HTTP URL"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in that post &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://groups.google.com/forum/?fromgroups=#!msg/google-code-hosting/FxpUkunjoYw/vjl7gejX0GcJ" target="_blank"&gt;https://groups.google.com/forum/?fromgroups=#!msg/google-code-hosting/FxpUkunjoYw/vjl7gejX0GcJ&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But not any helpful tips.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-inspect-in-asa-5510-messes-up-svn-authentication/m-p/2231518#M349939</guid>
      <dc:creator>vladimirtch</dc:creator>
      <dc:date>2019-03-12T01:43:12Z</dc:date>
    </item>
    <item>
      <title>http inspect in ASA 5510 messes up svn authentication</title>
      <link>https://community.cisco.com/t5/network-security/http-inspect-in-asa-5510-messes-up-svn-authentication/m-p/2231519#M349940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; See here on how the inspect actually works (for version 8.2) and maybe you find the reason why it gets blocked:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i2.html#wp1735782"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i2.html#wp1735782&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 14:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-inspect-in-asa-5510-messes-up-svn-authentication/m-p/2231519#M349940</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2013-05-15T14:10:40Z</dc:date>
    </item>
  </channel>
</rss>

