<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ip inspect problem, dropping important connections on 887VAMG ro in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ip-inspect-problem-dropping-important-connections-on-887vamg/m-p/1897848#M458469</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I removed a firewall, ip inspecting and ACLs, but there is some delays for web browsing and slow internet connection.This model of router C887VAMG was introduced just in January, so I'm wonder if there are some bugs in firmware.&lt;/P&gt;&lt;P&gt;Why is this router is not capable to do inspection and firewalling? It shouldn't really drop the performance so high.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Mar 2012 22:17:32 GMT</pubDate>
    <dc:creator>firestormnet</dc:creator>
    <dc:date>2012-03-14T22:17:32Z</dc:date>
    <item>
      <title>ip inspect problem, dropping important connections on 887VAMG router</title>
      <link>https://community.cisco.com/t5/network-security/ip-inspect-problem-dropping-important-connections-on-887vamg/m-p/1897847#M458467</link>
      <description>&lt;P&gt;Hi All.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a problem on 887VAMG router. It drops important connections. As customer wants to have a firewall I created ACL and ip inspect rules ,but the router drops their connections to cloud and some websites are not opening. So I removed ACL and most ip inspect rules just to test if it effects that. And left only ip inspect http urlfilter. But still they have those problems, so I'm really stuck how to configure that firewall. &lt;/P&gt;&lt;P&gt;I'll be highly appretiated for any help.&lt;/P&gt;&lt;P&gt;The below some dropping connection review:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%FW-6-DROP_PKT: Dropping tcp session&amp;nbsp; due to&amp;nbsp; RST inside current window with ip ident 13968 tcpflags 0x5014 seq.no 1629693318 ack 1687676045&lt;/P&gt;&lt;P&gt;000049: Mar&amp;nbsp; 6 11:49:21.324: %FW-6-DROP_PKT: Dropping http session &amp;lt;ip&amp;gt;:1766 69.171.242.12:80&amp;nbsp;&amp;nbsp;&amp;nbsp; with ip ident 26247 tcpflags 0x5018 seq.no 264144210 ack 642133125&lt;/P&gt;&lt;P&gt;000050: Mar&amp;nbsp; 6 11:50:00.774: %FW-6-DROP_PKT: Dropping http session &amp;lt;ip&amp;gt;:4708 69.171.242.12:80&amp;nbsp;&amp;nbsp;&amp;nbsp; with ip ident 2425 tcpflags 0x5018 seq.no 3819869211 ack 1862176018&lt;/P&gt;&lt;P&gt;000051: Mar&amp;nbsp; 6 11:50:52.515: %FW-6-DROP_PKT: Dropping http session &amp;lt;ip&amp;gt;:2599 173.194.34.90:80&amp;nbsp; due to&amp;nbsp; RST inside current window with ip ident 22909 tcpflags 0x5014 seq.no 899975979 ack 92642430&lt;/P&gt;&lt;P&gt;000052: Mar&amp;nbsp; 6 11:51:24.013: %FW-6-DROP_PKT: Dropping http session &amp;lt;ip&amp;gt;:4765 194.106.151.77:80&amp;nbsp; due to&amp;nbsp; RST inside current window with ip ident 4118 tcpflags 0x5014 seq.no 3161679649 ack 1450263460&lt;/P&gt;&lt;P&gt;068974: Mar&amp;nbsp; 6 05:10:14.676: %FW-6-DROP_PKT: Dropping http session 66.101.6.51:80 &amp;lt;ip&amp;gt;:1530&amp;nbsp; due to&amp;nbsp; RST inside current window with ip ident 8954 tcpflags 0x5014 seq.no 2056370527 ack 2999433041&lt;/P&gt;&lt;P&gt;068975: Mar&amp;nbsp; 6 05:35:48.385: %FW-6-DROP_PKT: Dropping http session 66.101.6.51:80 &amp;lt;ip&amp;gt;:1882&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 27148 tcpflags 0x5010 seq.no 939083425 ack 724203821&lt;/P&gt;&lt;P&gt;068976: Mar&amp;nbsp; 6 05:36:21.734: %FW-6-DROP_PKT: Dropping http session 66.101.6.51:80 &amp;lt;ip&amp;gt;:4919&amp;nbsp; due to&amp;nbsp; Stray Segment with ip ident 2945 tcpflags 0x5010 seq.no 704890853 ack 370246242&lt;/P&gt;&lt;P&gt;068977: Mar&amp;nbsp; 6 06:29:14.628: %FW-6-DROP_PKT: Dropping http session &amp;lt;ip&amp;gt;:1214 66.101.6.51:80&amp;nbsp; due to&amp;nbsp; Invalid Segment with ip ident 26797 tcpflags 0x7002 seq.no 2896034509 ack 0&lt;/P&gt;&lt;P&gt;068978: Mar&amp;nbsp; 6 06:32:51.923: %FW-6-DROP_PKT: Dropping http session 66.101.6.51:80 &amp;lt;ip&amp;gt;:1653&amp;nbsp; due to&amp;nbsp; SYN inside current window &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dropping http session due to&amp;nbsp; RST inside current window with ip.&lt;/P&gt;&lt;P&gt;Dropping http session due to&amp;nbsp; Stray Segment with ip.&lt;/P&gt;&lt;P&gt;These 2 are most of all. Why do they drop sessions? What do they mean?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-inspect-problem-dropping-important-connections-on-887vamg/m-p/1897847#M458467</guid>
      <dc:creator>firestormnet</dc:creator>
      <dc:date>2019-03-11T22:38:37Z</dc:date>
    </item>
    <item>
      <title>ip inspect problem, dropping important connections on 887VAMG ro</title>
      <link>https://community.cisco.com/t5/network-security/ip-inspect-problem-dropping-important-connections-on-887vamg/m-p/1897848#M458469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I removed a firewall, ip inspecting and ACLs, but there is some delays for web browsing and slow internet connection.This model of router C887VAMG was introduced just in January, so I'm wonder if there are some bugs in firmware.&lt;/P&gt;&lt;P&gt;Why is this router is not capable to do inspection and firewalling? It shouldn't really drop the performance so high.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2012 22:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-inspect-problem-dropping-important-connections-on-887vamg/m-p/1897848#M458469</guid>
      <dc:creator>firestormnet</dc:creator>
      <dc:date>2012-03-14T22:17:32Z</dc:date>
    </item>
  </channel>
</rss>

