<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem in accessing the http and https services using ASA v in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607055#M593527</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned in previous reply first message is about SYN timeout meaning the SYN went out but till 30 seconds we didn't receive any SYN+ACK, easy way to verify this or have a close look is to put captures on inside and outside interfaces and see the packet flow, if we see SYN going out and nothing is coming back then there is something causing problem after ASA (on outside) so it can be because of packet drop (may be congestion/slow link) but there can be other possibilities also depending upon network setup/environment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second message means that we received packet with FIN+ACK but the connection doesn't exist on firewall meaning firewall doesn't have that in connection table. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are few suggestions/points in addition to the reply from Jennifer, check packet captures to verify the behavior, if you bypass ASA (connect host directly to internet) then you still observe these issues? (if yes then I think we have found the problem &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; ) . Make sure that in network topology host s supposed to send traffic to ASA and ASA is sending that out to ISP (meaning no Asymmetric routing or issues at lower layer causing packets). For testing you may try bypassing ASA and one other test if needed is to connect host directly to ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as FTP is concerned that also involves three-way handshake so if FTP is used frequently then you should face problem with that one also unless traffic for FTP is not following same path (FTP on outside, client on inside) or the server we are trying for web has issue or it is not occurring much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shahid &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 22 Jan 2011 23:23:12 GMT</pubDate>
    <dc:creator>shzaman</dc:creator>
    <dc:date>2011-01-22T23:23:12Z</dc:date>
    <item>
      <title>Problem in accessing the http and https services using ASA very strange</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607052#M593524</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I need help from security gurus.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am unable to access the web sites and below error message appears when opening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some times websites are opened but most of time very slow and timed out. Extremely slow access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;92.122.208.146|80|172.19.110.21|1419|Teardown TCP connection 1045559 for outside:92.122.208.146/80 to inside:172.19.110.21/1419 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.19.110.21|1275|172.19.107.1|443|Deny TCP (no connection) from 172.19.110.21/1275 to 172.19.107.1/443 flags FIN ACK&amp;nbsp; on interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am fedup these error , can some one help me&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have below system versions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA&amp;nbsp;&amp;nbsp; 8.0 ( 2)&lt;/P&gt;&lt;P&gt;ASDM 6.2&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607052#M593524</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2019-03-11T19:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607053#M593525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Base on the error message, SYN timeout, it means that the server is not responding to TCP 3 way handshake as it is timing out on the TCP SYN packet.&lt;/P&gt;&lt;P&gt;You might want to check if the server is up and running correctly, and check the interface speed and duplex on the server. Is there any other server within the same zone that has the issue? or this is the only server that is having issue? If it's the only server who's having the issue, it's more likely a server issue than the ASA issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Jan 2011 17:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607053#M593525</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-01-22T17:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607054#M593526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also&amp;nbsp; think that 3 way TCP handshake is not going to complete&lt;/P&gt;&lt;P&gt;But this is happening all the hosts ( inside to outside means) accessing the internet from inside to hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am unable to access&amp;nbsp; the internet most of the time , some time web sites appears and normally this error comes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can this be due to the slow internet access ?&lt;/P&gt;&lt;P&gt;i have outside interface connected to VSAT internet modem and i am getting the 750 ~900 ms delay when trying to ping to yahoo.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also worth mentioning that FTP protocol has no issue .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could it be due to VSAT intenet or due to misconfiguration of ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Jan 2011 19:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607054#M593526</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-01-22T19:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607055#M593527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned in previous reply first message is about SYN timeout meaning the SYN went out but till 30 seconds we didn't receive any SYN+ACK, easy way to verify this or have a close look is to put captures on inside and outside interfaces and see the packet flow, if we see SYN going out and nothing is coming back then there is something causing problem after ASA (on outside) so it can be because of packet drop (may be congestion/slow link) but there can be other possibilities also depending upon network setup/environment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second message means that we received packet with FIN+ACK but the connection doesn't exist on firewall meaning firewall doesn't have that in connection table. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are few suggestions/points in addition to the reply from Jennifer, check packet captures to verify the behavior, if you bypass ASA (connect host directly to internet) then you still observe these issues? (if yes then I think we have found the problem &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; ) . Make sure that in network topology host s supposed to send traffic to ASA and ASA is sending that out to ISP (meaning no Asymmetric routing or issues at lower layer causing packets). For testing you may try bypassing ASA and one other test if needed is to connect host directly to ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as FTP is concerned that also involves three-way handshake so if FTP is used frequently then you should face problem with that one also unless traffic for FTP is not following same path (FTP on outside, client on inside) or the server we are trying for web has issue or it is not occurring much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shahid &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Jan 2011 23:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607055#M593527</guid>
      <dc:creator>shzaman</dc:creator>
      <dc:date>2011-01-22T23:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607056#M593528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Shahid,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for reply and support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand&lt;/P&gt;&lt;P&gt;My Firewall outside interface is directly connected with the Modem of the VSAT. No other things( device)&amp;nbsp; in between.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i directly connect host to the modem , Internet working perfectly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So whats wrong , i changed the cable between firewall and VSAT modem , nothing works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only option i left is to consider some problem in VSAT modem device . But VSAT provider asking that direct pc have no problem so his device is functioning properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Imran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 06:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607056#M593528</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-01-23T06:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607057#M593529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure about inside topology, have you tried to connect inside PC directly to ASA and test that. And share information about inside topology also. Check 'show asp drop' command and see if you are seeing any drops there , if yes then take that output and save it for reference then use 'clear asp drop' command to clear those counters and try to browse and after some time check if you are seeing any drops 'show asp drop' and share that output. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also share some information about device configuration, is there anything special configured like changed MSS or timeout values or traffic policing and what about HTTP inspection, is it enabled (try disabling that if possible). Also check CPU/memory usage also, is that showing anything abnormal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you will be interested in this video also, starting from 6th minute(approx)&amp;nbsp; &lt;SPAN&gt;Kureli Sankar (Cisco Engineer)&lt;/SPAN&gt; is discussing about the latency issues through firewall. &lt;/P&gt;&lt;P&gt;Link: &lt;A href="https://community.cisco.com/videos/1075"&gt;https://supportforums.cisco.com/videos/1075&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this will help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shahid&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 07:03:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607057#M593529</guid>
      <dc:creator>shzaman</dc:creator>
      <dc:date>2011-01-23T07:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607058#M593530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wanted to add one point, first check 'show int' output for speed/duplex settings and if there are any errors (CRC, collision etc.), if yes try clearing those and check after some time. By the way the link that I mentioned will have more information. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 07:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607058#M593530</guid>
      <dc:creator>shzaman</dc:creator>
      <dc:date>2011-01-23T07:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607059#M593531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has your server two NICs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 07:27:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607059#M593531</guid>
      <dc:creator>Oscar Cardiel</dc:creator>
      <dc:date>2011-01-23T07:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607060#M593532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Shahid&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes Drops has been seen on firewall&lt;/P&gt;&lt;P&gt;You can see out put below also no abnormal things like memory and CPU has been observed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;&amp;nbsp; No valid adjacency&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 552&lt;BR /&gt;&amp;nbsp; No route to host&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 273&lt;BR /&gt;&amp;nbsp; Flow is denied by configured rule&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2502848&lt;BR /&gt;&amp;nbsp; First TCP packet not SYN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 24127&lt;BR /&gt;&amp;nbsp; TCP data send after FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;BR /&gt;&amp;nbsp; TCP failed 3 way handshake&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 692&lt;BR /&gt;&amp;nbsp; TCP RST/FIN out of order&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2805&lt;BR /&gt;&amp;nbsp; TCP packet SEQ past window&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 57&lt;BR /&gt;&amp;nbsp; TCP invalid ACK&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&lt;BR /&gt;&amp;nbsp; TCP Out-of-0rder packet buffer full&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 87&lt;BR /&gt;&amp;nbsp; TCP Out-of-Order packet buffer timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 35&lt;BR /&gt;&amp;nbsp; TCP RST/SYN in window&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1918&lt;BR /&gt;&amp;nbsp; TCP DUP and has been ACKed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3169118&lt;BR /&gt;&amp;nbsp; Slowpath security checks failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3713&lt;BR /&gt;&amp;nbsp; IP option drop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1396&lt;BR /&gt;&amp;nbsp; ICMP Error Inspect different embedded conn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&lt;BR /&gt;&amp;nbsp; DNS Inspect invalid packet&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&lt;BR /&gt;&amp;nbsp; DNS Inspect invalid domain label&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 104&lt;BR /&gt;&amp;nbsp; DNS Inspect packet too long&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&lt;BR /&gt;&amp;nbsp; DNS Inspect id not matched&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13&lt;BR /&gt;&amp;nbsp; Interface is down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 45&lt;BR /&gt;&amp;nbsp; Dropped pending packets in a closed socket&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3434&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;&amp;nbsp; NAT failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14&lt;BR /&gt;&amp;nbsp; Inspection failure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2002&lt;BR /&gt;&amp;nbsp; SSL bad record detected&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 217&lt;BR /&gt;&amp;nbsp; SSL received close alert&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i have seen below config in firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;tcp-map mss-map&lt;BR /&gt;&amp;nbsp; exceed-mss allow&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are configurations for inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;class-map http-map1&lt;BR /&gt; match access-list http-list2&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;policy-map type inspect dns migrated_dns_map_1&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map http-map1&lt;BR /&gt; class http-map1&lt;BR /&gt;&amp;nbsp; set connection advanced-options mss-map&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 07:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607060#M593532</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-01-23T07:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607061#M593533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clear the drops using command 'clear asp drop' then after some time check how these are increasing and you may capture the packets getting dropped in ASP by using 'capture cap1 type asp-drop all' command and then do 'sh cap cap1' to check packets and use 'sh cap cap1 | in &lt;IP-ADDRESS&gt;' to see packets dropped for specific IP. &lt;/IP-ADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Information about these drop reasons can be found on link: &lt;A class="active_link" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s2.html#wp1351326"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s2.html#wp1351326&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Capture command help: &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c1.html#wp2108895"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c1.html#wp2108895&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about interface stats and as mentioned by user: Oscar about NIC cards? and have you tested by connecting PC directly to ASA? Also share output of 'sh service-policy' and 'sh asp drop' after clearing those and allow some time to pass. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shahid &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 07:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607061#M593533</guid>
      <dc:creator>shzaman</dc:creator>
      <dc:date>2011-01-23T07:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607062#M593534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Shahid&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for supporting me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the output after clearing and clearly showing that it is increasing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface stats are normal no crc and collissions and we have only one NIC in proxy server and also in other pcs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sh asp drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;&amp;nbsp; Flow is denied by configured rule&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77026&lt;BR /&gt;&amp;nbsp; First TCP packet not SYN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 540&lt;BR /&gt;&amp;nbsp; TCP failed 3 way handshake&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14&lt;BR /&gt;&amp;nbsp; TCP RST/FIN out of order&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 39&lt;BR /&gt;&amp;nbsp; TCP DUP and has been ACKed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 148&lt;BR /&gt;&amp;nbsp; Slowpath security checks failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 222&lt;BR /&gt;&amp;nbsp; Dropped pending packets in a closed socket&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow drop:&lt;BR /&gt;&amp;nbsp; Inspection failure&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 90&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Capture result is&amp;nbsp; ( note inside interface&amp;nbsp; is a 802.1q interface with two vlan( subinterfaces) , 107 and 301) 172.19.108.15 is our proxy server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;F01# sh cap cap1 | in 172.19.108.15&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp; 91: 10:38:10.315688 802.1Q vlan#107 P0 172.19.108.15.58153 &amp;gt; 209.85.146.147.80&lt;BR /&gt;: R 3801422935:3801422935(0) win 0&lt;BR /&gt; 109: 10:38:11.545442 802.1Q vlan#107 P0 172.19.108.15.59455 &amp;gt; 4.23.54.126.80: F&lt;BR /&gt; 2671847652:2671847652(0) ack 1948589870 win 65535&lt;BR /&gt; 110: 10:38:11.545442 802.1Q vlan#107 P0 172.19.108.15.59580 &amp;gt; 4.23.54.126.80: F&lt;BR /&gt; 158076312:158076312(0) ack 1566687617 win 65535&lt;BR /&gt; 111: 10:38:11.545442 802.1Q vlan#107 P0 172.19.108.15.52683 &amp;gt; 4.23.54.126.80: F&lt;BR /&gt; 296836186:296836186(0) ack 1325884648 win 65535&lt;BR /&gt; 124: 10:38:13.025206 802.1Q vlan#107 P0 172.19.108.15.62868 &amp;gt; 217.163.21.37.80:&lt;BR /&gt; R 947079666:947079666(0) win 0&lt;BR /&gt; 838: 10:39:08.774923 802.1Q vlan#107 P0 172.19.108.15.65386 &amp;gt; 172.19.109.11.25:&lt;BR /&gt; R 2405507004:2405507004(0) win 0&lt;BR /&gt; 911: 10:39:14.903792 802.1Q vlan#107 P0 172.19.108.15.52887 &amp;gt; 164.46.230.36.80:&lt;BR /&gt; F 11072808:11072808(0) ack 303114077 win 65535&lt;BR /&gt; 912: 10:39:14.903792 802.1Q vlan#107 P0 172.19.108.15.50048 &amp;gt; 164.46.230.36.80:&lt;BR /&gt; F 376466281:376466281(0) ack 1223761515 win 65535&lt;BR /&gt;1094: 10:39:50.212986 802.1Q vlan#107 P0 172.19.108.15.62417 &amp;gt; 209.85.146.139.80&lt;BR /&gt;: F 212350602:212350602(0) ack 1911057388 win 65535&lt;BR /&gt;1095: 10:39:50.212986 802.1Q vlan#107 P0 172.19.108.15.63620 &amp;gt; 209.85.146.113.80&lt;BR /&gt;: F 499560277:499560277(0) ack 2065700036 win 65535&lt;BR /&gt;1096: 10:39:50.212986 802.1Q vlan#107 P0 172.19.108.15.64893 &amp;gt; 218.145.28.57.80:&lt;BR /&gt; F 2683057573:2683057573(0) ack 2098978771 win 65535&lt;BR /&gt;2552: 10:41:20.496403 802.1Q vlan#107 P0 172.19.108.15.57191 &amp;gt; 124.83.230.247.80&lt;BR /&gt;: F 2402672053:2402672053(0) ack 408318225 win 65535&lt;BR /&gt;2553: 10:41:20.496403 802.1Q vlan#107 P0 172.19.108.15.59067 &amp;gt; 157.166.255.22.80&lt;BR /&gt;: F 1173855759:1173855759(0) ack 467500409 win 65535&lt;BR /&gt;2554: 10:41:20.496403 802.1Q vlan#107 P0 172.19.108.15.57435 &amp;gt; 218.145.28.57.80:&lt;BR /&gt; F 3958388812:3958388812(0) ack 188205860 win 65535&lt;BR /&gt;2555: 10:41:20.496403 802.1Q vlan#107 P0 172.19.108.15.61206 &amp;gt; 218.145.28.227.80&lt;BR /&gt;: F 3292236323:3292236323(0) ack 832932232 win 65535&lt;BR /&gt;2556: 10:41:20.496403 802.1Q vlan#107 P0 172.19.108.15.50084 &amp;gt; 93.184.220.33.80:&lt;BR /&gt; F 2001697565:2001697565(0) ack 1150791319 win 65535&lt;BR /&gt;2557: 10:41:20.496403 802.1Q vlan#107 P0 172.19.108.15.51883 &amp;gt; 59.106.108.72.80:&lt;BR /&gt; F 3044666264:3044666264(0) ack 927250299 win 65535&lt;BR /&gt;3091: 10:41:45.611784 802.1Q vlan#107 P0 172.19.108.15.54656 &amp;gt; 209.85.146.155.80&lt;BR /&gt;: R 2312296347:2312296347(0) win 0&lt;BR /&gt;3271: 10:41:54.180227 802.1Q vlan#107 P0 172.19.108.15.49255 &amp;gt; 209.85.146.19.80:&lt;BR /&gt; R 477269530:477269530(0) win 0&lt;BR /&gt;3787: 10:42:57.896560 802.1Q vlan#107 P0 172.19.108.15.53249 &amp;gt; 172.19.109.11.25:&lt;BR /&gt; R 3667559968:3667559968(0) win 0&lt;BR /&gt;4073: 10:43:28.800892 802.1Q vlan#107 P0 172.19.108.15.56241 &amp;gt; 209.85.146.104.80&lt;BR /&gt;: R 2897547054:2897547054(0) win 0&lt;BR /&gt;4541: 10:43:50.796849 802.1Q vlan#107 P0 172.19.108.15.49429 &amp;gt; 209.85.146.99.80:&lt;BR /&gt; R 3330175187:3330175187(0) win 0&lt;BR /&gt;4548: 10:43:50.896819 802.1Q vlan#107 P0 172.19.108.15.60681 &amp;gt; 209.85.146.99.80:&lt;BR /&gt; R 2132491876:2132491876(0) win 0&lt;BR /&gt;5404: 10:44:31.055127 802.1Q vlan#107 P0 172.19.108.15.49199 &amp;gt; 209.85.146.99.80:&lt;BR /&gt; R 1050183837:1050183837(0) win 0&lt;BR /&gt;5684: 10:44:44.452643 209.85.146.113.80 &amp;gt; 172.19.108.15.55546: . 568089835:56809&lt;BR /&gt;1215(1380) ack 1131064961 win 32240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Service policy output is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global policy:&lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rtsp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 38395, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny , packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip , packet 139, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 29459, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tried directly connecting PC to inside of firewall as then i have to remove the 802.1Q setting from inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advice&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 09:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607062#M593534</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-01-23T09:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607063#M593535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think these drops are for approx. 1 hrs (just guessing after looking at posts time), you may find detail about these drops on link mentioned in my previous message. I am not sure about complete flow of traffic like complete packet exchange (we may go for checking that) but I can see reset from proxy server and it is for port:80 traffic mainly, here is a sample&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3271: 10:41:54.180227 802.1Q vlan#107 P0 172.19.108.15.49255 &amp;gt; 209.85.146.19.80:&lt;BR /&gt;R 477269530:477269530(0) win 0&lt;BR /&gt;3787: 10:42:57.896560 802.1Q vlan#107 P0 172.19.108.15.53249 &amp;gt; 172.19.109.11.25:&lt;BR /&gt;R 3667559968:3667559968(0) win 0&lt;BR /&gt;4073: 10:43:28.800892 802.1Q vlan#107 P0 172.19.108.15.56241 &amp;gt; 209.85.146.104.80&lt;BR /&gt;: R 2897547054:2897547054(0) win 0&lt;BR /&gt;4541: 10:43:50.796849 802.1Q vlan#107 P0 172.19.108.15.49429 &amp;gt; 209.85.146.99.80:&lt;BR /&gt;R 3330175187:3330175187(0) win 0&lt;BR /&gt;4548: 10:43:50.896819 802.1Q vlan#107 P0 172.19.108.15.60681 &amp;gt; 209.85.146.99.80:&lt;BR /&gt;R 2132491876:2132491876(0) win 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In previous posts you mentioned that FTP works fine so FTP is also passing through the proxy or not? Here are few suggestion which should take us to conclusion&lt;/P&gt;&lt;P&gt;--Try to connect PC directly to ASA and see the performance (whenever it is possible) or may be if you have any interface free on ASA then configure that to have access to internet and connect system on that one.&lt;/P&gt;&lt;P&gt;--You may try bypassing the proxy also.&lt;/P&gt;&lt;P&gt;--One more point that on switch side on trunk interface only allow Vlans which are configured on ASA.&lt;/P&gt;&lt;P&gt;--Also share output of 'sh run all sysopt'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To me it looks like the issue is with internal side but we have to confirm that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shahid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 10:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607063#M593535</guid>
      <dc:creator>shzaman</dc:creator>
      <dc:date>2011-01-23T10:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607064#M593536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bypassing proxy also gives same result &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am actually very surprised that some time even we got very good speed and all services looks like resumed but after few minutes , situation becomes same. &lt;/P&gt;&lt;P&gt;on 301 vlan we also have same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ftp is using direct connection without proxy but without proxy i am also unable to browse .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the output of&amp;nbsp;&amp;nbsp; sh run all sysopt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no sysopt connection timewait&lt;BR /&gt;sysopt connection tcpmss 1380&lt;BR /&gt;sysopt connection tcpmss minimum 0&lt;BR /&gt;no sysopt nodnsalias inbound&lt;BR /&gt;no sysopt nodnsalias outbound&lt;BR /&gt;no sysopt radius ignore-secret&lt;BR /&gt;sysopt connection permit-vpn&lt;BR /&gt;no sysopt connection reclassify-vpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked On switch only two vlans are allowed&amp;nbsp; ( 107 and 301) on that trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/12&lt;BR /&gt; description To ASA5510&lt;BR /&gt; switchport trunk encapsulation dot1q&lt;BR /&gt; switchport trunk allowed vlan 107,301&lt;BR /&gt; switchport mode trunk&lt;BR /&gt; srr-queue bandwidth share 10 10 60 20&lt;BR /&gt; srr-queue bandwidth shape&amp;nbsp; 10&amp;nbsp; 0&amp;nbsp; 0&amp;nbsp; 0&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Imran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 11:26:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607064#M593536</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-01-23T11:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607065#M593537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We may go for checking complete packet exchange while we have issue to see what is happening wrong or if possible you may open TAC ticket to have Webex with some Cisco engineer and check all necessary things (if possible like having support agreement etc). But in addition to my last replies here are few suggestions (some points are may be duplicate)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Check switch side also for interface errors, speed/duplex because when you connect host directly to modem you observe normal speed so the things which are not there in that case are local LAN and ASA. &lt;/P&gt;&lt;P&gt;--Try connecting PC directly to ASA and check performance (already mentioned)&lt;/P&gt;&lt;P&gt;--Is there any other device doing layer-3 routing in network (other then ASA) then make sure your default gateways (for devices) are setup correctly and no asymmetric routing or redirection is happening. &lt;/P&gt;&lt;P&gt;--If you are not using any VPN (IPSec, SSL, GRE, l2tp etc.) then you may increase TCP MSS from 1380 to 1460 by using command 'sysopt connection tcpmss 1460' , this will allow more data to be there in TCP segment so it should effect performance positively and it depends upon applications also. But do this if you don't have any VPN.&lt;/P&gt;&lt;P&gt;--Check the video which I mentioned in my previous replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this will help you. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shahid &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Jan 2011 22:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607065#M593537</guid>
      <dc:creator>shzaman</dc:creator>
      <dc:date>2011-01-23T22:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in accessing the http and https services using ASA v</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607066#M593538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much all for support&lt;/P&gt;&lt;P&gt;Problem resolved and it was probably by due to performance issues on ISP side&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way thank you very much specialy by Mr. Shahid.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 06:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-accessing-the-http-and-https-services-using-asa-very/m-p/1607066#M593538</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-02-21T06:35:30Z</dc:date>
    </item>
  </channel>
</rss>

