<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can i see traffic being dropped by Firewall? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832210#M492303</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help guys. I have tried both methods and i still cant see what is blocking it. Do you have any idea what can cause this behavior in the firewall even after the inspect esmtp has been removed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Nov 2011 18:37:39 GMT</pubDate>
    <dc:creator>powermann</dc:creator>
    <dc:date>2011-11-28T18:37:39Z</dc:date>
    <item>
      <title>How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832207#M492299</link>
      <description>&lt;P&gt;Hi All. I have a problem where users on the inside of my network cannot receive emails when they use outlook and windows live to external mail servers. If email is unencrypted (eg hotmail) there are no issues. If however email is encrypted ( gmail on por 465 or outlook over ssl) then the users can receive but cannot send emails. I have already disable inspect esmpt and i have removed any outbound access-list. I want to see if there is anything elese that could be blocking the traffic. How can i do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Firewall config it attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marlon&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832207#M492299</guid>
      <dc:creator>powermann</dc:creator>
      <dc:date>2019-03-11T21:56:07Z</dc:date>
    </item>
    <item>
      <title>How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832208#M492301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can use packet-tracer or capture packets on the ASA to see which is the problem.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.brianyeager.org/?p=504"&gt;http://www.brianyeager.org/?p=504&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 16:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832208#M492301</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-11-28T16:06:12Z</dc:date>
    </item>
    <item>
      <title>How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832209#M492302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe that ASP drop captures will work for you here. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture asp type asp-drop all headers-only (With the headers-only the ASA won't capture the payload of the packet so the capture buffer won't fill so fast).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that if you do "show cap asp | inc" and then the IP address that you are tracking here you will be able to see if there are packets dropped by the ASA&amp;nbsp; (if any).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 17:38:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832209#M492302</guid>
      <dc:creator>josecalv</dc:creator>
      <dc:date>2011-11-28T17:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832210#M492303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help guys. I have tried both methods and i still cant see what is blocking it. Do you have any idea what can cause this behavior in the firewall even after the inspect esmtp has been removed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 18:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832210#M492303</guid>
      <dc:creator>powermann</dc:creator>
      <dc:date>2011-11-28T18:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832211#M492305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ASA is not dropping the packets and the ESMTP&amp;nbsp; inspection is disabled what's makes you believe that this is firewall&amp;nbsp; related? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to confirm that though. Could you share the&amp;nbsp; packet captures (in pcap format) of one outbound failing connection on&amp;nbsp; both incoming and outgoing interfaces of the firewall? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have had some cases related to this and they all&amp;nbsp; were problems related to the endpoints. Generally when an e-mail fails&amp;nbsp; you receive an e-mail back with an error code. Are you receiving any of those by any chance? Maybe that could help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 22:12:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832211#M492305</guid>
      <dc:creator>josecalv</dc:creator>
      <dc:date>2011-11-28T22:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832212#M492307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jose. I had by passed the firewall and the users worked fine. When they go back to their hotels they have no problems with emails. I even put a switch between the firewall and the outside/internet router and the email worked! &lt;/P&gt;&lt;P&gt;The only error you get is that there is a time out connecting to the server. &lt;/P&gt;&lt;P&gt;I will send the capture data when i get back to office. Thanks for your assistance. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2011 03:15:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832212#M492307</guid>
      <dc:creator>powermann</dc:creator>
      <dc:date>2011-11-29T03:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832213#M492308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you do that kind of tests there could be a lot of things that you could by bypassing as well. I am afraid to say that that is not a conclusive test as I have seen on many other cases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be waiting for the captures here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2011 14:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832213#M492308</guid>
      <dc:creator>josecalv</dc:creator>
      <dc:date>2011-11-29T14:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832214#M492309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Jose. I did a capture from my ip (172.17.12.100) going to smtp.gmail.com ( 74.125.157.102-109). The files are attached. Please let me know if you seen anything out of the ordinary. Much appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2011 17:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832214#M492309</guid>
      <dc:creator>powermann</dc:creator>
      <dc:date>2011-11-29T17:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: How can i see traffic being dropped by Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832215#M492310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All. I found a work around for the problem. I took Jose's advice and looked at it from the end point and found that windows 7 handles tcp windowing diffrently than previous OS's. I still think there is an issue somewhere but i am not sure where esle to look so i will work with this for now. &lt;/P&gt;&lt;P&gt;See note below. Thanks for your help guys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disable the auto tuning&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the state or current setting of TCP Auto-Tuning&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Open elevated command prompt with administrator’s privileges.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Type the following command and press Enter:&lt;/P&gt;&lt;P&gt;netsh interface tcp show global&lt;/P&gt;&lt;P&gt;The system will display the following text on screen, where you can check on the Auto-Tuning setting:&lt;/P&gt;&lt;P&gt;Querying active state…&lt;/P&gt;&lt;P&gt;TCP Global Parameters&lt;/P&gt;&lt;P&gt;———————————————-&lt;/P&gt;&lt;P&gt;Receive-Side Scaling State : enabled&lt;/P&gt;&lt;P&gt;Chimney Offload State : enabled&lt;/P&gt;&lt;P&gt;Receive Window Auto-Tuning Level : normal&lt;/P&gt;&lt;P&gt;Add-On Congestion Control Provider : none&lt;/P&gt;&lt;P&gt;ECN Capability : disabled&lt;/P&gt;&lt;P&gt;RFC 1323 Timestamps : disabled&lt;/P&gt;&lt;P&gt;Disable TCP Auto-Tuning&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Open elevated command prompt with administrator’s privileges.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Type the following command and press Enter:&lt;/P&gt;&lt;P&gt;netsh interface tcp set global autotuning=disabled&lt;/P&gt;&lt;P&gt;Enable TCP Auto-Tuning&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Open elevated command prompt with administrator’s privileges.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Type the following command and press Enter:&lt;/P&gt;&lt;P&gt;netsh interface tcp set global autotuning=normal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.mydigitallife.info/disable-tcp-auto-tuning-to-solve-slow-network-cannot-load-web-page-or-download-email-problems-in-vista/"&gt;http://www.mydigitallife.info/disable-tcp-auto-tuning-to-solve-slow-network-cannot-load-web-page-or-download-email-problems-in-vista/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Nov 2011 15:49:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-see-traffic-being-dropped-by-firewall/m-p/1832215#M492310</guid>
      <dc:creator>powermann</dc:creator>
      <dc:date>2011-11-30T15:49:23Z</dc:date>
    </item>
  </channel>
</rss>

