<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Maximum number of unanswered HTTP requests exceeded in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700701#M560996</link>
    <description>&lt;P&gt;Some http traffic seems to trigger the following syslog messages, generated by the 'inspect http' engine.&lt;/P&gt;&lt;P&gt;ASA-4-415016: policy-map dmz-policy:Maximum number of unanswered HTTP requests exceeded - Resetting connection from dmz01:xx.xx.xx.xx/33309 to prod01:yy.yy.yy.yy/80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the maximum number of unanswered HTTP requests anyway and how can I increase it? I've tried increasing it by setting per-client-embryonic-max to 100 in the policy. However, the connection policy hasn't dropped any packets. Were running 8.2(5) software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The cisco error message decoder says that the 'protocol-violation action' command should be entered to correct this. I have 'protocol-violation' action set to 'log', so it shouldn't drop or reset anything because of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface dmz01:&lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: dmz-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: htpp-traffic-class&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection policy: conn-max 10000 embryonic-conn-max 1000 per-client-max 250 per-client-embryonic-max 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; current embryonic conns 0, current conns 40, drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection timeout policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; idle 1:00:00 reset&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DCD: disabled, retry-interval 0:00:15, max-retries 5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DCD: client-probe 0, server-probe 0, conn-expiration 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: http http-policy, packet 205322, drop 982, reset-drop 982&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect http http-policy&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; protocol-violation action log&lt;/P&gt;&lt;P&gt;policy-map dmz-policy&lt;/P&gt;&lt;P&gt; class htpp-traffic-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; set connection conn-max 10000 embryonic-conn-max 1000 per-client-max 250 per-client-embryonic-max 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; set connection timeout idle 1:00:00 reset&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http http-policy&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:43:50 GMT</pubDate>
    <dc:creator>remcolamee</dc:creator>
    <dc:date>2019-03-11T20:43:50Z</dc:date>
    <item>
      <title>Maximum number of unanswered HTTP requests exceeded</title>
      <link>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700701#M560996</link>
      <description>&lt;P&gt;Some http traffic seems to trigger the following syslog messages, generated by the 'inspect http' engine.&lt;/P&gt;&lt;P&gt;ASA-4-415016: policy-map dmz-policy:Maximum number of unanswered HTTP requests exceeded - Resetting connection from dmz01:xx.xx.xx.xx/33309 to prod01:yy.yy.yy.yy/80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the maximum number of unanswered HTTP requests anyway and how can I increase it? I've tried increasing it by setting per-client-embryonic-max to 100 in the policy. However, the connection policy hasn't dropped any packets. Were running 8.2(5) software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The cisco error message decoder says that the 'protocol-violation action' command should be entered to correct this. I have 'protocol-violation' action set to 'log', so it shouldn't drop or reset anything because of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface dmz01:&lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: dmz-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: htpp-traffic-class&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection policy: conn-max 10000 embryonic-conn-max 1000 per-client-max 250 per-client-embryonic-max 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; current embryonic conns 0, current conns 40, drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set connection timeout policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; idle 1:00:00 reset&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DCD: disabled, retry-interval 0:00:15, max-retries 5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DCD: client-probe 0, server-probe 0, conn-expiration 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: http http-policy, packet 205322, drop 982, reset-drop 982&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect http http-policy&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; protocol-violation action log&lt;/P&gt;&lt;P&gt;policy-map dmz-policy&lt;/P&gt;&lt;P&gt; class htpp-traffic-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; set connection conn-max 10000 embryonic-conn-max 1000 per-client-max 250 per-client-embryonic-max 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; set connection timeout idle 1:00:00 reset&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http http-policy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:43:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700701#M560996</guid>
      <dc:creator>remcolamee</dc:creator>
      <dc:date>2019-03-11T20:43:50Z</dc:date>
    </item>
    <item>
      <title>Maximum number of unanswered HTTP requests exceeded</title>
      <link>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700702#M560997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The maximum number of unanswered HTTP requests is 10 and cannot be increased. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 13:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700702#M560997</guid>
      <dc:creator>Anu M Chacko</dc:creator>
      <dc:date>2011-06-10T13:31:25Z</dc:date>
    </item>
    <item>
      <title>Maximum number of unanswered HTTP requests exceeded</title>
      <link>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700703#M560998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So how can I inspect http traffic to my proxyservers and webservers without causing proxy-errors? I'am using http inspection to inspect the traffic from my http proxy server to webservers as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 14:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700703#M560998</guid>
      <dc:creator>remcolamee</dc:creator>
      <dc:date>2011-06-10T14:15:31Z</dc:date>
    </item>
    <item>
      <title>Maximum number of unanswered HTTP requests exceeded</title>
      <link>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700704#M560999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Remco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what you meant by "proxy-errors". If the connections are getting reset even though the action is "log", then you might have to exempt traffic to the servers from HTTP inspection, since more than 10 requests cannot be held. Do give it a try and let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 15:41:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700704#M560999</guid>
      <dc:creator>Anu M Chacko</dc:creator>
      <dc:date>2011-06-10T15:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of unanswered HTTP requests exceeded</title>
      <link>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700705#M561000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for replying Anu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me explain the 'proxy-errors'. The proxyserver is a reverse proxy, protecting the webservers by beeing an application gateway / session terminator. When a http session gets droped / reset by the firewall, the browser reports 'proxy error'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Browser ---&amp;gt; DMZ Firewall ---&amp;gt; Reverse proxy server ---&amp;gt; Firewall ---&amp;gt; Webservers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, both firewalls are reporting errors ASA-4-415016 during normal http sessions. I could exempt this traffic from inspection and let the proxy server take care of http protocol inspection. However, this would mean that the cisco http inspection is not up to the job of protecting webservers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Jun 2011 05:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-number-of-unanswered-http-requests-exceeded/m-p/1700705#M561000</guid>
      <dc:creator>remcolamee</dc:creator>
      <dc:date>2011-06-12T05:31:40Z</dc:date>
    </item>
  </channel>
</rss>

