<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Initial connections to sql servers timeout through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/initial-connections-to-sql-servers-timeout-through-asa/m-p/2064435#M438889</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: justify;"&gt;Hi Bro&lt;/P&gt;&lt;P style="text-align: justify;"&gt;Based on your problem description, I personally don't think this is an issue with your Cisco Firewall. The reason being, you said &lt;EM&gt;"The problem server is a webserver that connects back through the firewall to access the SQL server on port 1433. We also have many other webservers in the DMZ which access the same SQL server, but do not have the same timeout issues."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;Since all the other Web Servers in DMZ has no issues accessing the SQL server except for this particular one, then what I would propose you to do is to perform 2 packet captures from within the Cisco Firewall i.e. from the non-working Web Server to the SQL server and from a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; working Web Server to the SQL server and compare the packet capture output. Chances are this could be an application scripting issue. Let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're not sure on how to perform packet captures from within your Cisco Firewall, please refer to this URL; &lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 25 Aug 2012 13:30:14 GMT</pubDate>
    <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
    <dc:date>2012-08-25T13:30:14Z</dc:date>
    <item>
      <title>Initial connections to sql servers timeout through ASA</title>
      <link>https://community.cisco.com/t5/network-security/initial-connections-to-sql-servers-timeout-through-asa/m-p/2064434#M438888</link>
      <description>&lt;P&gt;I am on version 8.2(1) of ASA Code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When accessing a SQL server on a secure internal interface,(Traffic is sourcing from DMZ) i'm getting some timeouts on the initial connection on port 1433.&amp;nbsp;&amp;nbsp; All subsequent connections work fine.&amp;nbsp;&amp;nbsp; Packet tracer shows the connection builds properly, and shouldn't have a connectivity issue.&amp;nbsp;&amp;nbsp; The problem server is a webserver that connects back through the firewall to access the SQL server on port 1433.&amp;nbsp;&amp;nbsp;&amp;nbsp; We also have many other webservers in the DMZ which access the same SQL server, but do not have the same timeout issues.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are my timeouts, from the config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've seen a couple articles about increasing the tcp timeout to 3 hours for the DMZ interface, but I'm not sure that's the best idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have an idea what might be wrong?&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/initial-connections-to-sql-servers-timeout-through-asa/m-p/2064434#M438888</guid>
      <dc:creator>lcnorwood</dc:creator>
      <dc:date>2019-03-11T23:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Initial connections to sql servers timeout through ASA</title>
      <link>https://community.cisco.com/t5/network-security/initial-connections-to-sql-servers-timeout-through-asa/m-p/2064435#M438889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: justify;"&gt;Hi Bro&lt;/P&gt;&lt;P style="text-align: justify;"&gt;Based on your problem description, I personally don't think this is an issue with your Cisco Firewall. The reason being, you said &lt;EM&gt;"The problem server is a webserver that connects back through the firewall to access the SQL server on port 1433. We also have many other webservers in the DMZ which access the same SQL server, but do not have the same timeout issues."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;Since all the other Web Servers in DMZ has no issues accessing the SQL server except for this particular one, then what I would propose you to do is to perform 2 packet captures from within the Cisco Firewall i.e. from the non-working Web Server to the SQL server and from a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; working Web Server to the SQL server and compare the packet capture output. Chances are this could be an application scripting issue. Let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're not sure on how to perform packet captures from within your Cisco Firewall, please refer to this URL; &lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2012 13:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/initial-connections-to-sql-servers-timeout-through-asa/m-p/2064435#M438889</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-25T13:30:14Z</dc:date>
    </item>
  </channel>
</rss>

