<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with Service Policy not applied on traffic... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176947#M359987</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the output from "show service-policy":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh service-policy"&lt;/P&gt;&lt;P&gt;Global policy: &lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: Oracle-DK09&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection policy:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection timeout policy:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; idle 8:00:00 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DCD: disabled, retry-interval 0:00:15, max-retries 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DCD: client-probe 0, server-probe 0, conn-expiration 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dcerpc, packet 8557686, lock fail 0, drop 1511, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 385738, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225 _default_h323_map, packet 4, lock fail 0, drop 0, reset-drop 1, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 133&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras _default_h323_map, packet 3, lock fail 0, drop 3, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ip-options _default_ip_options_map, packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rtsp, packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip , packet 884, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny , packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 20344251, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 166, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 1020838, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Default Queueing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection policy:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection decrement-ttl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Gustaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Mar 2013 06:51:21 GMT</pubDate>
    <dc:creator>itr05Eurofins</dc:creator>
    <dc:date>2013-03-22T06:51:21Z</dc:date>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176939#M359976</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a quite new setup with ASA 5545-X and using it for WAN-firewalling to protect our Datacenter from the rest of our organization.&lt;BR /&gt;We have had trouble with specific Oracle-traffic from one site that gets broken down after 1 hour of idle time in the client-application.&lt;BR /&gt;What I would like to do is to raise the Timeout-value to 8 hours for traffic to that specific Oracle host from the problematic site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Orcale host has this "fake" IP 192.168.101.100 (Destination_Host)&lt;BR /&gt;And the site with problem has this "fake" IP-network: 192.168.102.0/24 (Source_Network)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The source and destination are on different interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone advice me what's wrong in this configuration?&lt;BR /&gt;Because when I run a Packet Trace in ASDM it doesn't show any trace of hitting this specific Class (Specific_Host_Traffic) and corresponding Class-Map. The config is made from ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;BR /&gt;/Gustaf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;object network Source_Network&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;subnet 192.168.102.0 255.255.255.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;object network Destination_Host&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;host 192.168.101.100&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;multiple access-lists&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list global_mpc extended permit ip object Source_Network object Destination_Host&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map inspection-default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map Specific_Host_Traffic&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;match access-list global_mpc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map inspection_default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;match default-inspection-traffic&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map netflow&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;match any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;policy-map type inspect dns preset_dns_map&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;parameters&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;message-length maximum client auto&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;message-length maximum 512&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;policy-map global-policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;policy-map global_policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class Specific_Host_Traffic&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;set connection timeout idle 8:00:00&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class inspection_default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect dcerpc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect ftp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect h323 h225&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect h323 ras&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect ip-options&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect rsh&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect rtsp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect sip&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect skinny&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect sqlnet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect sunrpc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect tftp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;inspect xdmcp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class class-default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;set connection decrement-ttl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;service-policy global_policy global&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Morten Sandholdt&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:15:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176939#M359976</guid>
      <dc:creator>itr05Eurofins</dc:creator>
      <dc:date>2019-03-12T01:15:29Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176940#M359978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try to create a specific Access-list only for this traffic? Get it out of the "global_mpc" group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do a "&lt;STRONG&gt;show local X.X.X.X&lt;/STRONG&gt;" where X.X.X.X is the internal IP of the host from the internal network and confirm that t is connecting to 192.168.101.100.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 20:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176940#M359978</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-18T20:17:10Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176941#M359981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; How do you mean with " try to create a specific Access-list only for this traffic? Get it out of the "global_mpc" group"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did it through ASDM so I'm not a master in CLI. &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did see the traffic being built and also getting torn down in the Logs. So I'm convinced it's the correct addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Gustaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 22:16:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176941#M359981</guid>
      <dc:creator>itr05Eurofins</dc:creator>
      <dc:date>2013-03-18T22:16:11Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176942#M359982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Morten,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you do a second ACL in teh opposite way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list global_mpc extended permit ip object Destination_Host object Source_Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible, please also share the logs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Juan Lombana&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 22:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176942#M359982</guid>
      <dc:creator>julomban</dc:creator>
      <dc:date>2013-03-18T22:23:05Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176943#M359983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I mean that we can create a unique set of Access-lists just for the traffic we want to match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[first and only rule]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list IDLE-T extended permit ip object Source_Network object Destination_Host&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;class-map Specific_Host_Traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;match access-list IDLE-T&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;policy-map global_policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;class Specific_Host_Traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;set connection timeout idle 8:00:00&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you still share the output of the "&lt;STRONG&gt;show local X.X.X.X details&lt;/STRONG&gt;" command? It can be used to confirm the values we are configuring. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 00:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176943#M359983</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-19T00:55:44Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176944#M359984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi. Thanks for the replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Havn't had the possibility to change the ACL yet. Will do tonight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an output from show local with the current config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show local 192.168.102.7 detail"&lt;/P&gt;&lt;P&gt;Interface WAN-MPLS-Links: 1962 active, 3253 maximum active, 0 denied&lt;BR /&gt;local host: &amp;lt;192.168.102.7&amp;gt;,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 13/unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP WAN-MPLS-Links: 192.168.102.7/63799 WAN-L2-R5-Links: 192.168.101.100/1526,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags UIOB , idle 25m20s, uptime 25m21s, timeout 1h0m, bytes 4452&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP WAN-MPLS-Links: 192.168.102.7/63795 WAN-L2-R5-Links: 192.168.101.100/1526,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags UIOB , idle 3m14s, uptime 25m38s, timeout 1h0m, bytes 367567&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;THERE were="" more="" conns="" here="" to="" other="" servers=""&gt;&lt;/THERE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 07:40:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176944#M359984</guid>
      <dc:creator>itr05Eurofins</dc:creator>
      <dc:date>2013-03-19T07:40:45Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176945#M359985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wanted to inform that we don't have any other rules/ACLs/ACEs for global_mpc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We haven't used it before so it's just that rule above. Nothing more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Gustaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 07:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176945#M359985</guid>
      <dc:creator>itr05Eurofins</dc:creator>
      <dc:date>2013-03-19T07:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176946#M359986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One more thing,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mind posting the output of the "&lt;STRONG&gt;show service-policy&lt;/STRONG&gt;" command from the unit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration as it is should work and the output of the "&lt;STRONG&gt;show local&lt;/STRONG&gt;" command should be showing 8 hrs instead of 1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 02:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176946#M359986</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-20T02:35:54Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176947#M359987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the output from "show service-policy":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh service-policy"&lt;/P&gt;&lt;P&gt;Global policy: &lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: Oracle-DK09&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection policy:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection timeout policy:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; idle 8:00:00 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DCD: disabled, retry-interval 0:00:15, max-retries 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DCD: client-probe 0, server-probe 0, conn-expiration 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dcerpc, packet 8557686, lock fail 0, drop 1511, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 385738, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225 _default_h323_map, packet 4, lock fail 0, drop 0, reset-drop 1, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 133&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras _default_h323_map, packet 3, lock fail 0, drop 3, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ip-options _default_ip_options_map, packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rtsp, packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip , packet 884, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny , packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 20344251, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 166, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 1020838, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Default Queueing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection policy:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection decrement-ttl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Gustaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 06:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176947#M359987</guid>
      <dc:creator>itr05Eurofins</dc:creator>
      <dc:date>2013-03-22T06:51:21Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176948#M359988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, it just looks like it is not matching the class-map we created for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's remove the policy-map and apply it again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no service-policy global_policy global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; service-policy global_policy global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, let's clear all the connections going to &lt;STRONG&gt;"&lt;/STRONG&gt;192.168.101.100&lt;STRONG&gt;".&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Clear local 192.168.101.100&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should do it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 23:19:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176948#M359988</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-22T23:19:17Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176949#M359989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, I will test that. So if I run &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no service-policy global_policy global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;there is no risk that the configurations regarding the service-policys gets removed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I run version 9.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just want's to be sure. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Gustaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Mar 2013 22:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176949#M359989</guid>
      <dc:creator>itr05Eurofins</dc:creator>
      <dc:date>2013-03-24T22:45:26Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176950#M359990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The configurations will remain, they will just won't be applied to the traffic while the command is off.&lt;/P&gt;&lt;P&gt;Won't cause any problems, it might actually fix'em. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Mar 2013 22:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176950#M359990</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-24T22:49:45Z</dc:date>
    </item>
    <item>
      <title>Problem with Service Policy not applied on traffic...</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176951#M359991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jocamare!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Big Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no service-policy global_policy global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;service-policy global_policy global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Clear local 192.168.101.100&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It Works!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Apr 2013 06:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-service-policy-not-applied-on-traffic/m-p/2176951#M359991</guid>
      <dc:creator>itr05Eurofins</dc:creator>
      <dc:date>2013-04-02T06:51:43Z</dc:date>
    </item>
  </channel>
</rss>

