<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic http traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979230#M409496</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Prashant ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; where you are performing your dynamic nating in same firewall or in some other device ?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) My insight is on your firewall config , as you said already your firewall is servcing for internet with global PATing . so over here your firewall is performing same PATing for your Application HTTP server .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) To Avoid usage of&amp;nbsp; global PATing , uses access-list based dynamic NATing on your firewall . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible post your firewall system configuration it will be greatful for the resolution . This only configuration error .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Thks&lt;/P&gt;&lt;P&gt;Santhosh Sarav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Aug 2012 02:28:35 GMT</pubDate>
    <dc:creator>sansarav720e</dc:creator>
    <dc:date>2012-08-17T02:28:35Z</dc:date>
    <item>
      <title>http traffic</title>
      <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979225#M409490</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing a typical issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two router router x and router y.connected to one firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For particular&amp;nbsp; vlan&amp;nbsp; i have diverted the traffic from firewall to a diffrent router(with a dedicated link for vlan).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just asuume gmail ,hotmail etc all traffic flows fromfireall is diverted router x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for one http trraafic (http application given by client flows through router y from firewall)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Link is of 2 Mbps for 10 users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is&amp;nbsp; the user who connects first connects to that aplication via http traffic has no problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when other two to thrre users connects to that application via hhtp traffic than all the users starts facing problem including the first user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The recomended bandwidth for 10 users is 1mbps. But we have dedicated 2 Mbps bandwidth for that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note- client have provided some public ip for that hhtp traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for that public ip we have given diffrent route from firewall.&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:41:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979225#M409490</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2019-03-11T23:41:46Z</dc:date>
    </item>
    <item>
      <title>http traffic</title>
      <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979226#M409491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Prashant ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; kindly let me for following things ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is this same vlan need to access open internet &amp;amp; http application &lt;/P&gt;&lt;P&gt;2) Are you familar with application server IP address ?? &lt;/P&gt;&lt;P&gt;3) Are you doing PATing or Static NATing for your LAN segment&lt;/P&gt;&lt;P&gt;4) Does your firewall has been defined with specfic route pointing to your application server to use your 2Mbps circuit .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your firewall should have static routing with application server subnet to use your 2Mbps circuit .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know on this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Thks&lt;/P&gt;&lt;P&gt;Santhosh Sarav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 05:02:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979226#M409491</guid>
      <dc:creator>sansarav720e</dc:creator>
      <dc:date>2012-08-14T05:02:22Z</dc:date>
    </item>
    <item>
      <title>http traffic</title>
      <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979227#M409492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; HI ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As i already mentioned with one user evertthing work fine for 20 to 25 vminutes and than suddenly gets hanged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i captured the packect i found some duplicate packet along with retransmission of packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is related anyrhing to MTU Or mss settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bandwidth is never the issue,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2012 14:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979227#M409492</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2012-08-15T14:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: http traffic</title>
      <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979228#M409493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Prashant ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; My insight over here is suspecting something on your NATing ,if you have done Static Nating or dynamic nating&amp;nbsp; this will allow only one user session , if you have only 1 public IP address in&amp;nbsp; your global pool for your internal network transalation to external world .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Try to configure PATing , if you have already configured PATing check for port utilisation , if it exceeds 64000 then u ll have problem , for our scenarion we have only 10 user so there should not be any problem for PATing .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Similalry check at client side http application server , does it allow multiple user session from a single public routable IP address , if it has got restriction to 1 then u need to have multiple induidual routable IP address for each user&amp;nbsp; or Customer owned IP Private IP address for this resolution .&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dynamic NAT has these disadvantages: &lt;/P&gt;&lt;P&gt;&lt;A name="wp1079314"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;If the mapped pool has fewer addresses than the real group, you could run out of addresses if the amount of traffic is more than expected. &lt;/P&gt;&lt;P&gt;&lt;A name="wp1079315"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Use PAT if this event occurs often because PAT provides over 64,000 translations using ports of a single address. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1079316"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;You have to use a large number of routable addresses in the mapped pool; if the destination network requires registered addresses, such as the Internet, you might encounter a shortage of usable addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_dynamic.html#wp1078484" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_dynamic.html#wp1078484&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Thks&lt;/P&gt;&lt;P&gt;Santhosh Sarav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 02:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979228#M409493</guid>
      <dc:creator>sansarav720e</dc:creator>
      <dc:date>2012-08-16T02:06:55Z</dc:date>
    </item>
    <item>
      <title>http traffic</title>
      <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979229#M409494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi santosh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today one&amp;nbsp; activity was carried out by me .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With same dynamic nat policy it worked well for 10 users.The onething change was i bypassed the firewall in between of that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But with same firewall it works well for one user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On firewall I have an access-list permit ip any any.I donot know what exactly the problem is on firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no ips module on it also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 14:25:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979229#M409494</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2012-08-16T14:25:35Z</dc:date>
    </item>
    <item>
      <title>http traffic</title>
      <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979230#M409496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Prashant ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; where you are performing your dynamic nating in same firewall or in some other device ?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) My insight is on your firewall config , as you said already your firewall is servcing for internet with global PATing . so over here your firewall is performing same PATing for your Application HTTP server .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) To Avoid usage of&amp;nbsp; global PATing , uses access-list based dynamic NATing on your firewall . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible post your firewall system configuration it will be greatful for the resolution . This only configuration error .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Thks&lt;/P&gt;&lt;P&gt;Santhosh Sarav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 02:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979230#M409496</guid>
      <dc:creator>sansarav720e</dc:creator>
      <dc:date>2012-08-17T02:28:35Z</dc:date>
    </item>
    <item>
      <title>http traffic</title>
      <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979231#M409498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have directed the traffic from firewall and natted on router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 03:23:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979231#M409498</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2012-08-17T03:23:55Z</dc:date>
    </item>
    <item>
      <title>http traffic</title>
      <link>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979232#M409499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Prashant ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Could you please share your firewall configuration . Does your firewall is running PATing for general internet access&amp;nbsp; ??? . &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 04:02:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-traffic/m-p/1979232#M409499</guid>
      <dc:creator>sansarav720e</dc:creator>
      <dc:date>2012-08-17T04:02:27Z</dc:date>
    </item>
  </channel>
</rss>

