<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with Certain Websites redirecting traffic and coming in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-certain-websites-redirecting-traffic-and-coming/m-p/1700204#M558097</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the error message number? Is it &lt;SPAN class="pEM_ErrMsg"&gt;%ASA-6-106015? If so &lt;/SPAN&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;this guide may offer some help:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-14491"&gt;https://supportforums.cisco.com/docs/DOC-14491&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Potentially you could enable TCP bypass, however this&amp;nbsp; will also disable all TCP-based security checks and application inspection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Apr 2011 12:50:28 GMT</pubDate>
    <dc:creator>sean_evershed</dc:creator>
    <dc:date>2011-04-11T12:50:28Z</dc:date>
    <item>
      <title>Problem with Certain Websites redirecting traffic and coming back through firewall</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-certain-websites-redirecting-traffic-and-coming/m-p/1700203#M558088</link>
      <description>&lt;P&gt;Let me quickly explain our setup, we are running a cisco ASA 5510.&amp;nbsp; We have 2 linux proxy servers in the DMZ. Both Proxy servers have static NAT on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;50% of websites we go to through the firewall have no problems. The other 50% times out, we have found that this happens mostly to websites that are web 2.0 (like facebook) and redirect their traffic to other websites. We then decided to test using wget on the linux boxes. This bypasses the proxy component and is a simple download tool for linux. The same thing applies where direct connections to files work fine but redirection breaks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WSG01-EXT is the proxy server. WSG01-PUBLIC-BROWSING is the outside NAT. Here I am trying to download a file.&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://download.winzip.com/winzip150.exe" target="_blank"&gt;http://download.winzip.com/winzip150.exe&lt;/A&gt;&lt;SPAN&gt; . The ip address I am connecting to and the ip address that responds is not the same one and it makes sense that the firewall blocks it as it sent no syn to that address, but how do i get around this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some relavant firewall logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WSG01-EXT&amp;nbsp;&amp;nbsp;&amp;nbsp; 39701&amp;nbsp;&amp;nbsp;&amp;nbsp; 92.123.154.73&amp;nbsp;&amp;nbsp;&amp;nbsp; 80&amp;nbsp;&amp;nbsp;&amp;nbsp; Built outbound TCP connection 201329 for outside:92.123.154.73/80 (92.123.154.73/80) to DMZ-VLAN-15:WSG01-EXT/39701 (WSG01-PUBLIC-BROWSING/39701)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;165.165.47.11&amp;nbsp;&amp;nbsp;&amp;nbsp; 80&amp;nbsp;&amp;nbsp;&amp;nbsp; WSG01-PUBLIC-BROWSING&amp;nbsp;&amp;nbsp;&amp;nbsp; 30737&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny TCP (no connection) from 165.165.47.11/80 to WSG01-PUBLIC-BROWSING/30737 flags SYN ACK&amp;nbsp; on interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for all the replies and let me know if you need more information. I really hope this is just some kind of checkbox somewhere that I am missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-certain-websites-redirecting-traffic-and-coming/m-p/1700203#M558088</guid>
      <dc:creator>ssteenkamp</dc:creator>
      <dc:date>2019-03-11T20:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Certain Websites redirecting traffic and coming</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-certain-websites-redirecting-traffic-and-coming/m-p/1700204#M558097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the error message number? Is it &lt;SPAN class="pEM_ErrMsg"&gt;%ASA-6-106015? If so &lt;/SPAN&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;this guide may offer some help:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-14491"&gt;https://supportforums.cisco.com/docs/DOC-14491&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Potentially you could enable TCP bypass, however this&amp;nbsp; will also disable all TCP-based security checks and application inspection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 12:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-certain-websites-redirecting-traffic-and-coming/m-p/1700204#M558097</guid>
      <dc:creator>sean_evershed</dc:creator>
      <dc:date>2011-04-11T12:50:28Z</dc:date>
    </item>
  </channel>
</rss>

