<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Skinny inspection closes connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/skinny-inspection-closes-connection/m-p/1828530#M489653</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ASA's security policy denies all traffic except TCP/2000, the inspection would be needed to allow the child connections through after the initial TCP/2000 control channel establishes. You would also need to have the inspection enabled if the ASA is performing any NAT on the Skinny traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best tools to debug the Skinny inspection are debugging (7) level syslogs, 'debug skinny' output, and simultaneous, bi-directional packet captures taken on both sides of the ASA. I would recommend opening a TAC case for additional assistance if the above output doesn't make the issue more clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jan 2012 18:11:06 GMT</pubDate>
    <dc:creator>mirober2</dc:creator>
    <dc:date>2012-01-06T18:11:06Z</dc:date>
    <item>
      <title>Skinny inspection closes connection</title>
      <link>https://community.cisco.com/t5/network-security/skinny-inspection-closes-connection/m-p/1828529#M489647</link>
      <description>&lt;P&gt;I have a branch office set up were all traffic goes back to the core, iincluding internet acces. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has been working fine for a year, but recently I have started to see the firewalls Asa 5505 closing the connection and stopping the phone from answering the calls. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have skinny inspection turned on all my branch offices, but had to turn it off at the one site to get one of my phones to registered. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't made any changes to the network that would trigger this issue, such as upgrading phone firmware. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My firewall is configured for default deny, other than Skinny (tcp 2000), do I need Skinny inspection to be turned on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's turned on my 5 other branches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I debug why the skinny inspection is closing the connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a separate note this phone is part of a pool of phones that shares a common DN, would this be causing the issue?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:08:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/skinny-inspection-closes-connection/m-p/1828529#M489647</guid>
      <dc:creator>martinbuffleo</dc:creator>
      <dc:date>2019-03-11T22:08:57Z</dc:date>
    </item>
    <item>
      <title>Skinny inspection closes connection</title>
      <link>https://community.cisco.com/t5/network-security/skinny-inspection-closes-connection/m-p/1828530#M489653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ASA's security policy denies all traffic except TCP/2000, the inspection would be needed to allow the child connections through after the initial TCP/2000 control channel establishes. You would also need to have the inspection enabled if the ASA is performing any NAT on the Skinny traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best tools to debug the Skinny inspection are debugging (7) level syslogs, 'debug skinny' output, and simultaneous, bi-directional packet captures taken on both sides of the ASA. I would recommend opening a TAC case for additional assistance if the above output doesn't make the issue more clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 18:11:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/skinny-inspection-closes-connection/m-p/1828530#M489653</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2012-01-06T18:11:06Z</dc:date>
    </item>
  </channel>
</rss>

