<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Http Connection with Video Flow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700440#M556498</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using ASA 5510 and I have a specific problem with Http Connection to receive a video Flow ( RSTP protocol ) in the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some Pc users (192.168.1.133,in the log)&amp;nbsp; with ASA Lan Interface as gateway can ping the Camera but don't receveive the video flow.&lt;BR /&gt;Some Pc users (192.168.1.116,in the log) using another gateway can ping and receive the video flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used Whireshark&amp;nbsp; to capture traffic between camera and Pc using the 2 gateway. I joined Logs with this message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to be a problem of TCP segments on the ASA, I try to changed some TCP options but it's still the same:&lt;BR /&gt;- Disable Force Maximum Segment Size&lt;BR /&gt;- Enable Force TCP Connection to Linger in TIME_WAIT State for at Least 15 Second&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I enable RSTP inspection for example ? Any Others Ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:29:37 GMT</pubDate>
    <dc:creator>avburren1</dc:creator>
    <dc:date>2019-03-11T20:29:37Z</dc:date>
    <item>
      <title>Http Connection with Video Flow</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700440#M556498</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using ASA 5510 and I have a specific problem with Http Connection to receive a video Flow ( RSTP protocol ) in the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some Pc users (192.168.1.133,in the log)&amp;nbsp; with ASA Lan Interface as gateway can ping the Camera but don't receveive the video flow.&lt;BR /&gt;Some Pc users (192.168.1.116,in the log) using another gateway can ping and receive the video flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used Whireshark&amp;nbsp; to capture traffic between camera and Pc using the 2 gateway. I joined Logs with this message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to be a problem of TCP segments on the ASA, I try to changed some TCP options but it's still the same:&lt;BR /&gt;- Disable Force Maximum Segment Size&lt;BR /&gt;- Enable Force TCP Connection to Linger in TIME_WAIT State for at Least 15 Second&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I enable RSTP inspection for example ? Any Others Ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700440#M556498</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2019-03-11T20:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Http Connection with Video Flow</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700441#M556499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please disable HTTP inspection if enable and enable RTSP inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 18:53:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700441#M556499</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-05T18:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: Http Connection with Video Flow</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700442#M556500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Http inspection is disabled and I rectify my first post , RTSP inspection is already enabled ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 21:28:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700442#M556500</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2011-05-05T21:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: Http Connection with Video Flow</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700443#M556501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I didnt understand that, you put it on question marks, it sounded like you were asking. Now, is the service policy giving you any drops on the RTSP? What can you see on the logs? Were you able to put an asp drop capture to check if the ASA is dropping any packets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 21:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700443#M556501</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-05T21:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Http Connection with Video Flow</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700444#M556502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw the logs but those deny tcp no connections were when the connection was already torn down. Please gather the reason why the first connection is being torn down so we can correlate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 21:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700444#M556502</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-05T21:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Http Connection with Video Flow</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700445#M556504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's why I ask here why the TCP connection doesn't work when PC use ASA Firewall as gateway whereas the ping is Ok.&lt;/P&gt;&lt;P&gt;Wireshark shows:&lt;/P&gt;&lt;P&gt;Acked Lost Segment /&amp;nbsp; Broken TCP. The acknowledge field is nonzero while the ACK flag is not set&lt;/P&gt;&lt;P&gt;I was wondering if ASA had&amp;nbsp; Security options with TCP connection which explain the deny traffic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 May 2011 09:53:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700445#M556504</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2011-05-06T09:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Http Connection with Video Flow</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700446#M556506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNoSpacing" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000;"&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR;"&gt;I just see a cisco documentation :&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000;"&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"&gt;&lt;SPAN style="color: black; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;EM&gt;The following restrictions apply to the &lt;STRONG&gt;inspect rtsp&lt;/STRONG&gt; command &lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR;"&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: black; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR; mso-fareast-font-family: 'Times New Roman';"&gt;&lt;P class="MsoNoSpacing" style="margin: 0cm 0cm 0pt;"&gt;&lt;EM&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR;"&gt;•&lt;/SPAN&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-fareast-language: FR; mso-no-proof: yes;"&gt; &lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR;"&gt;The security appliance does not have the ability to recognize HTTP cloaking where RTSP messages are hidden in the HTTP messages. &lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0cm 0cm 0pt;"&gt;&lt;EM&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR;"&gt;&lt;/SPAN&gt;&lt;/EM&gt; &lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 9.5pt; mso-ansi-language: EN-US; mso-fareast-language: FR;"&gt;Could it be an explanation to the problem ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 May 2011 15:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700446#M556506</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2011-05-06T15:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Http Connection with Video Flow</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700447#M556508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nobody ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to search other possibility :&lt;/P&gt;&lt;P&gt;When it works (pc using a different gateway), wireshark indicate this msg : Tcp segment of a reassembled PDU.&lt;BR /&gt;By default,Is the ASA accept and fragment frames larger than the MTU size ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what about the Timeout tcp-proxy-reassembly option ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 May 2011 14:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700447#M556508</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2011-05-11T14:53:27Z</dc:date>
    </item>
    <item>
      <title>Did you ever get  an answer</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700448#M556510</link>
      <description>&lt;P&gt;Did you ever get&amp;nbsp; an answer to this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2014 15:32:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-with-video-flow/m-p/1700448#M556510</guid>
      <dc:creator>Christopher Stock</dc:creator>
      <dc:date>2014-11-14T15:32:55Z</dc:date>
    </item>
  </channel>
</rss>

