<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,  the F5 is deployed in in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510350#M45520</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the F5 is deployed in one-arm configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also suspecting the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any problem if we have a 100Mpbs connection between ASA and IPS while others are in 1000Mbps?&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jun 2014 06:39:47 GMT</pubDate>
    <dc:creator>Anuar Shahrin</dc:creator>
    <dc:date>2014-06-18T06:39:47Z</dc:date>
    <item>
      <title>TCP out-of-order at IPS</title>
      <link>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510346#M45516</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a setup the IPS 4510 working inline mode with strict inspection turn on. we have detected some latency issue accessing the internal website. So we did some capture at the IPS interface. We found that there's a lot of out-of-order packet and DUP ACK detected by IPS which causing the normalizer engine buffer full and could not handle anymore request. As a work around we put the IPS in asymmetric mode where it turn off the IPS normalizer engine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some opinion on possibilities why the Out of order and DUP ACK happen.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are seeing quite a lot of Out-of-order, DUP ACK and TCP zero window in TCP stream that we captured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The topology is quite straight forward:&lt;/P&gt;&lt;P&gt;Internet ----WAN ROUTER ----- IPS4510 ----- ASA ----- Web server&lt;/P&gt;&lt;P&gt;There's no redundancy or load balance for the ASA or WANROUTER.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im hoping for some opinion and idea on how to tackle this issue.&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:12:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510346#M45516</guid>
      <dc:creator>Anuar Shahrin</dc:creator>
      <dc:date>2019-03-10T13:12:36Z</dc:date>
    </item>
    <item>
      <title>Hello, For which traffic do</title>
      <link>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510347#M45517</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;For which traffic do you have this problem, did you try any other tcp session for same ip and port. Could you share ASA logging for this traffic. generally firewalls block tcp traffic when it gets out of order packets you can listen traffic with wireshark on server site and trace tcp traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 06:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510347#M45517</guid>
      <dc:creator>mhnedirli</dc:creator>
      <dc:date>2014-06-18T06:12:07Z</dc:date>
    </item>
    <item>
      <title>Hi,Thanks for the reply</title>
      <link>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510348#M45518</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Unfortunately Im unable to access the ASA right now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did the capture at the IPS where we are seeing the out-of-order packet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may refer the capture. Unfortunately i could not show the IP. The IP is a public IP which we did the nat at ASA from our internal network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically at the idea of the IP is as below:&lt;/P&gt;&lt;P&gt;2.2.2.2 ---- ASA NAT ------ F5 BIG-IP :192.168.100.100---- Web Accelerator : 192.168.100.20( it has 4 itnerface connected to the server with the same range of IP and Gateway to ASA FW.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 06:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510348#M45518</guid>
      <dc:creator>Anuar Shahrin</dc:creator>
      <dc:date>2014-06-18T06:17:16Z</dc:date>
    </item>
    <item>
      <title>Hi, Could you check F5</title>
      <link>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510349#M45519</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you check F5 session table, in the middle a device blocking your SYN+ACK packet.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 06:30:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510349#M45519</guid>
      <dc:creator>mhnedirli</dc:creator>
      <dc:date>2014-06-18T06:30:27Z</dc:date>
    </item>
    <item>
      <title>Hi,  the F5 is deployed in</title>
      <link>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510350#M45520</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the F5 is deployed in one-arm configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also suspecting the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any problem if we have a 100Mpbs connection between ASA and IPS while others are in 1000Mbps?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 06:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510350#M45520</guid>
      <dc:creator>Anuar Shahrin</dc:creator>
      <dc:date>2014-06-18T06:39:47Z</dc:date>
    </item>
    <item>
      <title>Hi,Yes, check the MTU size of</title>
      <link>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510351#M45521</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes, check the MTU size of devices, maybe IPS site try to send big packet because of MTU size, other device in the network will try to fragment this packet, maybe ASA etc. blocks the fragmented packets. Try to change MSS size &amp;nbsp;for the TCP traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 08:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510351#M45521</guid>
      <dc:creator>mhnedirli</dc:creator>
      <dc:date>2014-06-18T08:28:36Z</dc:date>
    </item>
    <item>
      <title>Hibumping out an old thread</title>
      <link>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510352#M45523</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;bumping out an old thread since the issue still on going.&lt;/P&gt;&lt;P&gt;I already discussed with TAC regarding the issue and 2 option that she gave&lt;/P&gt;&lt;P&gt;+ asymmetric mode (Which we rejected as permanent solution)&lt;/P&gt;&lt;P&gt;+ Event action filter&lt;/P&gt;&lt;P&gt;I'm currently looking at this solution and plan to implement it in the IPS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to consider a few things and also suggestion&lt;/P&gt;&lt;P&gt;+ The signature engine involve is Normalizer engine (specifically sig 1330)&lt;/P&gt;&lt;P&gt;+ is it possible to customize this signature or should we just go for Event action filter?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;need opinion and pro and cons of this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a bunch&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2014 00:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-out-of-order-at-ips/m-p/2510352#M45523</guid>
      <dc:creator>Anuar Shahrin</dc:creator>
      <dc:date>2014-11-19T00:52:14Z</dc:date>
    </item>
  </channel>
</rss>

