<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SQL Inspect Issue... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053769#M397878</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Harish for quick response. Will their be any kind of distruption while removing sql inspect?&lt;/P&gt;&lt;P&gt; we are not doing natting for SQL server but yes at customer end their are some sort of nattings &amp;amp; multipule firewalls (juniper , asa etc). Is their any way we can simulate &amp;amp; know what is causing SQL inspect reset?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Oct 2012 06:07:13 GMT</pubDate>
    <dc:creator>yogesh.suryawanshi</dc:creator>
    <dc:date>2012-10-09T06:07:13Z</dc:date>
    <item>
      <title>SQL Inspect Issue...</title>
      <link>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053767#M397876</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we do have ASA 5510 with IOS Version 8.0(4).User from inside connects to SQL database in customer place which is at outside. Users can run smaller database queries however they can not run logners queries &amp;amp; get ora-03113 error on client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we found sql inspect reset increasing by 1 when user tries to connect each time.&lt;/P&gt;&lt;P&gt;Do that mean we need to disable / remote sql inspect form global service policy. Following is policy config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need expert advise on following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Do we need to remove sql inspect from service policy&lt;/P&gt;&lt;P&gt;2. will their be any impact while removing policy&lt;/P&gt;&lt;P&gt;3. Is their any way to bypass this specific flow the sql inspect (because dont know if other communications / users may need it)&lt;/P&gt;&lt;P&gt;4. steps to remove sql inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns preset_dns_map, packet 632, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 240935, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225 _default_h323_map, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras _default_h323_map, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rtsp, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: esmtp _default_esmtp_map, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 1817867, drop 0, reset-drop 1796&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny , packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip , packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 285, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 4894, drop 0, reset-drop 0&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053767#M397876</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2019-03-12T00:06:24Z</dc:date>
    </item>
    <item>
      <title>SQL Inspect Issue...</title>
      <link>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053768#M397877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Yogesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you are seeing the reset in sqlnet everytime the issue happens, its a good try to remove the inspection&amp;nbsp; for testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you doing NAT for the sql server in the ASA ? and do you have any other ASA at the other end ( then you need to remove the inspection from their end as well)&amp;nbsp; make sure that you have proper permission both inbound and outbound direction for both sql server and the client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can remove the inspection as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;no inspect sqlnet&lt;/P&gt;&lt;P&gt;exi&lt;/P&gt;&lt;P&gt;exi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; clear local-host all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 05:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053768#M397877</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-10-09T05:53:40Z</dc:date>
    </item>
    <item>
      <title>SQL Inspect Issue...</title>
      <link>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053769#M397878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Harish for quick response. Will their be any kind of distruption while removing sql inspect?&lt;/P&gt;&lt;P&gt; we are not doing natting for SQL server but yes at customer end their are some sort of nattings &amp;amp; multipule firewalls (juniper , asa etc). Is their any way we can simulate &amp;amp; know what is causing SQL inspect reset?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 06:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053769#M397878</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2012-10-09T06:07:13Z</dc:date>
    </item>
    <item>
      <title>SQL Inspect Issue...</title>
      <link>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053770#M397879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Yogesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It may reset the connection while removing the command but after that, there is no negetive impact.&lt;/P&gt;&lt;P&gt;coming back to you issue, when SQL inspection is on,&amp;nbsp; ASA will reduce the client window size 65000 to about 16000 which impact the data transfer, i guess that is what you are experiancing now. Please make sure that you are disabling this in all the&amp;nbsp; firewall on the patch and take care of the outside - inside communication as well ( Preferebly all UDP/TCP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you have any other questions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 06:16:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053770#M397879</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-10-09T06:16:59Z</dc:date>
    </item>
    <item>
      <title>SQL Inspect Issue...</title>
      <link>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053771#M397880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Harish.&lt;/P&gt;&lt;P&gt;Is their any way to bypass sqlinspect for particular source &amp;amp; destination. If Yes Kindly guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Yogesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 06:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053771#M397880</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2012-10-09T06:59:00Z</dc:date>
    </item>
    <item>
      <title>SQL Inspect Issue...</title>
      <link>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053772#M397881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Yogesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That can be done as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;access-list acl_sql_inspect deny tcp &lt;SUBNET of="" sql=""&gt; any &lt;/SUBNET&gt;&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;access-list acl_sql_inspect permit tcp any any &lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;!&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;class-map inspect_sql&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;match access-list acl_sql_inspect&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;!&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;policy-map global_policy&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;class inspection_default &lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;no inspect sqlnet&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;class-map inspect_sql &lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;inspect sqlnet&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;so it will only bypass the inspection for your prefered traffic defined in the acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="line-height: 98%; margin: 7.5pt 0in; background: white;"&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 07:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sql-inspect-issue/m-p/2053772#M397881</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-10-09T07:08:17Z</dc:date>
    </item>
  </channel>
</rss>

