<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can PIX/ASA disable stateful check? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217005#M418409</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way to disable the STATE check on the ASA (bypass the 3 way handshake for example) is to use the static nat command with the "nailed" option as well as the failover timeout &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1414075" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1414075&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Feb 2009 02:07:35 GMT</pubDate>
    <dc:creator>Ivan Martinon</dc:creator>
    <dc:date>2009-02-03T02:07:35Z</dc:date>
    <item>
      <title>Can PIX/ASA disable stateful check?</title>
      <link>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217004#M418407</link>
      <description>&lt;P&gt;Hi, all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one ASA 5510 with software 7.0, configurated as transparent firewall. Now I want to disable its stateful check, Anyone can tell me whether it support this feature? If its a routed firewall,can it support, And what is the command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tao&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:15:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217004#M418407</guid>
      <dc:creator>hetao1601</dc:creator>
      <dc:date>2020-02-21T11:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: Can PIX/ASA disable stateful check?</title>
      <link>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217005#M418409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way to disable the STATE check on the ASA (bypass the 3 way handshake for example) is to use the static nat command with the "nailed" option as well as the failover timeout &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1414075" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1414075&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2009 02:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217005#M418409</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-03T02:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can PIX/ASA disable stateful check?</title>
      <link>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217006#M418410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;imartino&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. From the explanation, it said nailed is used with 'failover timeout' command. What is that mean? I just want to disable the state check, so that asymmetric route traffic can pass through the pix. Can it support that? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, I'd like to know whether it can be used on the transparent mode since it doesn't have the 'static' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. It seem the following command is related with tcp state check.&lt;/P&gt;&lt;P&gt;   invalid-ack {allow | drop} &lt;/P&gt;&lt;P&gt;   Am I right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any reply is very appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tao&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2009 07:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217006#M418410</guid>
      <dc:creator>hetao1601</dc:creator>
      <dc:date>2009-02-03T07:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can PIX/ASA disable stateful check?</title>
      <link>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217007#M418412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regardless of transparent firewall statics are supported, and the failover timeout is a requirement when enabling "nailed" option. please take a look at the  command reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1414075" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1414075&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2009 15:10:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-pix-asa-disable-stateful-check/m-p/1217007#M418412</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-03T15:10:39Z</dc:date>
    </item>
  </channel>
</rss>

