<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyone ever disable sqlnet inspection during active Oracle c in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442754#M662395</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Show service-policy definitely shows processed packets.&amp;nbsp; Below is the output between back to back commands (~ 1 second apart).&amp;nbsp; Correct, we are using static identity NAT for the Oracle servers on the inside, and a "debug sqlnet" shows only port 1521 (INFO: intercepted port is 1521).&amp;nbsp; Therefore, it doesn't look like sqlnet inspection is needed.&amp;nbsp; Have you ever disabled it during active Oracle connections?&amp;nbsp; I want to disable it, but I'm afraid that it will bounce all Oracle connections, at which point, we'd need to restart a whole bunch of application servers. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FWSM# sho service-pol&lt;/P&gt;&lt;P&gt;Global policy:&lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns maximum-length 512, packet 104891795, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 1540053619, drop 126, reset-drop 9&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 596580, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 836274856, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 278078, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dcerpc, packet 10601143, drop 18, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class_sip_tcp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip, packet 0, drop 0, reset-drop 0&lt;BR /&gt;FWSM#&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FWSM# sho service-pol&lt;/P&gt;&lt;P&gt;Global policy:&lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns maximum-length 512, packet 104891905, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 1540053721, drop 126, reset-drop 9&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 596580, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 836285544, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 278078, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dcerpc, packet 10601143, drop 18, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class_sip_tcp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip, packet 0, drop 0, reset-drop 0&lt;BR /&gt;FWSM#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Jun 2010 18:38:53 GMT</pubDate>
    <dc:creator>pcoughlin01</dc:creator>
    <dc:date>2010-06-30T18:38:53Z</dc:date>
    <item>
      <title>Anyone ever disable sqlnet inspection during active Oracle connections?</title>
      <link>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442752#M662353</link>
      <description>&lt;P&gt;Running FWSM 3.2(9) in a datacenter with active Oracle connections from an outside vlan to an inside vlan.&amp;nbsp; Sqlnet inspection is enabled, however I don't believe it is needed, so I want to disable for possible performance improvement.&amp;nbsp; If I remove the inspection while active Oracle connections are open through the firewall, will they get dropped (of course this assumes the sqlnet inspection isn't needed).&amp;nbsp;&amp;nbsp; Anyone ever done that?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442752#M662353</guid>
      <dc:creator>pcoughlin01</dc:creator>
      <dc:date>2019-03-11T18:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever disable sqlnet inspection during active Oracle c</title>
      <link>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442753#M662369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls. issue "sh service-policy" and make sure whether the sql inspection is processing packets and if they increment by issuing the same command again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inspection does two things, NAT fixup and dynamically opening ports as needed without the need for ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May be you are not doing any address translation or you are doing just identity translation and if you remove inspection then, make sure the ACLs allow the ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jun 2010 18:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442753#M662369</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-06-30T18:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever disable sqlnet inspection during active Oracle c</title>
      <link>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442754#M662395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Show service-policy definitely shows processed packets.&amp;nbsp; Below is the output between back to back commands (~ 1 second apart).&amp;nbsp; Correct, we are using static identity NAT for the Oracle servers on the inside, and a "debug sqlnet" shows only port 1521 (INFO: intercepted port is 1521).&amp;nbsp; Therefore, it doesn't look like sqlnet inspection is needed.&amp;nbsp; Have you ever disabled it during active Oracle connections?&amp;nbsp; I want to disable it, but I'm afraid that it will bounce all Oracle connections, at which point, we'd need to restart a whole bunch of application servers. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FWSM# sho service-pol&lt;/P&gt;&lt;P&gt;Global policy:&lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns maximum-length 512, packet 104891795, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 1540053619, drop 126, reset-drop 9&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 596580, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 836274856, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 278078, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dcerpc, packet 10601143, drop 18, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class_sip_tcp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip, packet 0, drop 0, reset-drop 0&lt;BR /&gt;FWSM#&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FWSM# sho service-pol&lt;/P&gt;&lt;P&gt;Global policy:&lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns maximum-length 512, packet 104891905, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 1540053721, drop 126, reset-drop 9&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 596580, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 836285544, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 278078, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dcerpc, packet 10601143, drop 18, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: class_sip_tcp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip, packet 0, drop 0, reset-drop 0&lt;BR /&gt;FWSM#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jun 2010 18:38:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442754#M662395</guid>
      <dc:creator>pcoughlin01</dc:creator>
      <dc:date>2010-06-30T18:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever disable sqlnet inspection during active Oracle c</title>
      <link>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442755#M662421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The connections that are up will not be terminated. Any new connections will not be inspeted and if ACLs do not allow will be denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can remove inspection.&amp;nbsp; If you are worried you can remove the inspection later in the day when the load will be low.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jun 2010 18:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442755#M662421</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-06-30T18:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever disable sqlnet inspection during active Oracle c</title>
      <link>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442756#M662456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info.&amp;nbsp; Will give it a try at our next maintenance window, and will post the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2010 14:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyone-ever-disable-sqlnet-inspection-during-active-oracle/m-p/1442756#M662456</guid>
      <dc:creator>pcoughlin01</dc:creator>
      <dc:date>2010-07-01T14:13:20Z</dc:date>
    </item>
  </channel>
</rss>

