<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Enk, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164923#M351535</link>
    <description>&lt;P&gt;Thanks Enk,&lt;/P&gt;
&lt;P&gt;I had this problems just couple of days ago, &amp;nbsp;but the strange thing was the ASA was denying the SQL trafffic tcp/1521 from the wrong interface. For example the database is located on the outside and the client on the inside, &amp;nbsp;the traffic from the database is shown to be denied by the ASA from the inside, No NAT is being used on the ASA and ip any any on both interfaces did not show any effects.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also SFTP is being used between the client and the database. Am seeing syn timeout.&lt;/P&gt;
&lt;P&gt;Has anyone seen this behavior before? Please help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jun 2016 06:41:31 GMT</pubDate>
    <dc:creator>abashoru</dc:creator>
    <dc:date>2016-06-03T06:41:31Z</dc:date>
    <item>
      <title>ASA Oracle SQLNET Disconnects</title>
      <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164919#M351531</link>
      <description>&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;I wanted to make a post to help other people. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;I have an ASA5585-40 FO pair running 8.4.5 code in my data center that protects various subnets containing oracle servers and application servers.&amp;nbsp; After installing the FW with wide open IP ANY ANY rules we noticed things broke.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;The first thing we did was disable SQLNET global policy inspection.&amp;nbsp; It's know to be a pile of junk.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;The next thing we did was create a global service policy to match TCP/1521 traffic with an ACL&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;We&amp;nbsp; then set TCP connection properties on those streams to include the&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; following details:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Timeout=3:00:00&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Reset enabled&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;DCD enabled&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Retry interval 00:05:00&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Retry times=5&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt; &lt;/LI&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;We also configured the TCP normalization options in another TCP map on these streams.&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Disabled the "Clear Urgent flag" to allow URG flags&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt; &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;I am posting this because default ASA settings are not shown in the config file and I could not find this stuff anywhere on Netpro or Google.&amp;nbsp; There seemed to be a lot of different firewall and Oracle related trouble with a lot of different solutions that did not work for us.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Some Oracle applications will loose connectivity to the database if the application server sets the urgent flag in TCP packets.&amp;nbsp; I'm not willing to speculate on which types of Oracle applications use this flag, but all of our do and they flat out refused to connect to the database if the flag is not set. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;By default the ASA will remove URG flags.&amp;nbsp; The result is, you will have disconnected sessions as the ASA will see the connections as timed out and discard them.&amp;nbsp; By setting the TCP nomalization map to allow URG flags, your applications should function normally.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial, helvetica, sans-serif;"&gt;Enabling Dead Connection Detection will keep database connections alive so the hard TCP timeout value wont kill off long running DB process connections.&amp;nbsp; This allows you to maintain a shorter TCP global limit and only adjust limits on traffic that really needs them set higher.&amp;nbsp; This will help keep your ASA from crashing due to memory issues or causing the sate or connection tables form getting so full that they cannot accept any new connections.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0in; border: none; padding: 0in;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Our Oracle environment is crazy, but I am sure that I am not the only person that has had these issues.&amp;nbsp; GL, I hope this helps someone else.&amp;nbsp; It's been driving my nuts for the last two days.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164919#M351531</guid>
      <dc:creator>enkrypter</dc:creator>
      <dc:date>2019-03-12T01:30:48Z</dc:date>
    </item>
    <item>
      <title>ASA Oracle SQLNET Disconnects</title>
      <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164920#M351532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear friend ,&lt;/P&gt;&lt;P&gt;Thanks for your post , I had same problem as you with Oracle and Cisco ASA . Fortunately my problem has been solved with your solution .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 10:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164920#M351532</guid>
      <dc:creator>moghadasi_ha</dc:creator>
      <dc:date>2013-05-23T10:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Oracle SQLNET Disconnects</title>
      <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164921#M351533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Too bad I am unable to endorse actual starting posts. Only replies. Since this would indeed be some helpfull information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also had to deal with similiar problems as you and have had to resort creating special policys for just this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And to clarify about the "endorsement", I mean the following&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/community/netpro/idea-center/cafe/blog/2012/07/27/cisco-designated-vip-endorsed-program"&gt;https://supportforums.cisco.com/community/netpro/idea-center/cafe/blog/2012/07/27/cisco-designated-vip-endorsed-program&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 11:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164921#M351533</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-23T11:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Oracle SQLNET Disconnects</title>
      <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164922#M351534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;enkrypter wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0in; border: medium none; padding: 0in;"&gt;&lt;SPAN style="color: #333333; font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;&lt;EM&gt;&lt;STRONG&gt;Enabling Dead Connection Detection will keep database connections alive so the hard TCP timeout value wont kill off long running DB process connections.&lt;/STRONG&gt;&lt;/EM&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt; I could have told you this two years ago &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/laugh.gif"&gt;&lt;/SPAN&gt;.&amp;nbsp; That's what we did to our environment to get around issues like this.&amp;nbsp; Does not matter if you have Cisco ASA or Checkpoint firewalls &lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/silly.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For those that are interested, you can just enable keepalive for sqlnet on the database sqlnet.ora file.&amp;nbsp; Here is the syntax:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SQLNET.EXPIRE_TIME = 1 (in minute).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this secnario, every 60 seconds (however, the very first keepalive will start in 2 minutes after the connection is established), the database will probe the client with a keepalive packet of about 10 bytes.&amp;nbsp; In your tcpdump you will see something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;21:58:18.572337 IP 192.168.1.70.1521 &amp;gt; 192.168.15.7.2345: P 6436:6446(10) ack 6199 win 46644&lt;/P&gt;&lt;P&gt;21:58:18.697282 IP 192.168.15.7.2345 &amp;gt; 192.168.1.70.1521: . ack 6446 win 64677&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is highly recommended when you have database connection going across the firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my 2c &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 01:32:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164922#M351534</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-05-24T01:32:33Z</dc:date>
    </item>
    <item>
      <title>Thanks Enk,</title>
      <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164923#M351535</link>
      <description>&lt;P&gt;Thanks Enk,&lt;/P&gt;
&lt;P&gt;I had this problems just couple of days ago, &amp;nbsp;but the strange thing was the ASA was denying the SQL trafffic tcp/1521 from the wrong interface. For example the database is located on the outside and the client on the inside, &amp;nbsp;the traffic from the database is shown to be denied by the ASA from the inside, No NAT is being used on the ASA and ip any any on both interfaces did not show any effects.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also SFTP is being used between the client and the database. Am seeing syn timeout.&lt;/P&gt;
&lt;P&gt;Has anyone seen this behavior before? Please help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 06:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164923#M351535</guid>
      <dc:creator>abashoru</dc:creator>
      <dc:date>2016-06-03T06:41:31Z</dc:date>
    </item>
    <item>
      <title>Hello</title>
      <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164924#M351536</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have replaced our FWSM with the cisco ASA 5585-x (SSP-60).We have configured them in cluster mode. But&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;some Oracle applications are losing connectivity to the database&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;after replacement of Firewalls, Frequently&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The error on the application server is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;“Failed getting connection - at oradatabase.cpp(101) ORA-12547 : TNS: lost contact”&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And error on the ASA is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;“Deny TCP (no connection) from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN&gt;appserver_ip&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN&gt;/54864 to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN&gt;database_server_ip&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN&gt;/1521 flags FIN ACK on interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN&gt;Application_server_interface.”&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The first thing we created IP ANY ANY rules on the interface that belongs to applications.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;According to forum suggestions, we have disabled SQLNET global policy inspection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The next thing, we have created a service policy (interface base) to match our application to database connection on TCP/1521 protocol.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Then we have setted up TCP connection properties on those streams to include the following details:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Timeout=0:00:00&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;unlimited&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Reset enabled&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;DCD enabled&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Retry interval 00:15:00&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Retry times=5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We also have configured TCP map in the TCP normalization options on that:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Setted the reserved bits on “Allow only”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabled the "Clear Urgent flag" to allow URG flags&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabled the “Drop Connection on window variation”.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabled the “Drop Packets that exceed maximum segment size”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabled the “check if retransmitted data is the same as original”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabled the “Drop SYN packets with data”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Enable TTL evasion protection.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabled the “Verify TCP checksum”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabled the “Drop SYNACK packets with data”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Disabled the “Drop packets with invalid ACK”.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;And in TCP option just “clear window scale” has enabled.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Does inspection on SQLNET ineffect by disabling SQLNET global policy inspection?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What‘s wrong with us?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 17:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164924#M351536</guid>
      <dc:creator>MKH</dc:creator>
      <dc:date>2017-08-04T17:37:38Z</dc:date>
    </item>
    <item>
      <title>1.  I would not recommend</title>
      <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164925#M351537</link>
      <description>&lt;P&gt;1. &amp;nbsp;I would not recommend setting any timeout value to unlimited. &amp;nbsp;You run the risk of memory exhaustion or causing your ASA to no longer accept new connections.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. &amp;nbsp;You should not need interface access rules that permit IP any any. &amp;nbsp;If this is done right, you should only need to permit applications to talk over TCP/1521 to the database.&lt;/P&gt;
&lt;P&gt;3. &amp;nbsp;See attachment for ASDM configuration screenshots.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 18:44:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164925#M351537</guid>
      <dc:creator>enkrypter</dc:creator>
      <dc:date>2017-08-04T18:44:52Z</dc:date>
    </item>
    <item>
      <title>Hello</title>
      <link>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164926#M351538</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I really appreciate your help and assistance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you set The &amp;nbsp;&lt;EM&gt;SQLNET.EXPIRE_TIME &lt;/EM&gt;parameter in your database?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Does&amp;nbsp;the&lt;I&gt;&amp;nbsp;&lt;EM&gt;SQLNET.EXPIRE_TIME&amp;nbsp;&lt;/EM&gt;&lt;/I&gt;parameter in your database have default&amp;nbsp;value?What is that&amp;nbsp;quantity?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2017 04:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-oracle-sqlnet-disconnects/m-p/2164926#M351538</guid>
      <dc:creator>MKH</dc:creator>
      <dc:date>2017-08-06T04:40:43Z</dc:date>
    </item>
  </channel>
</rss>

