<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: asa&amp;gre in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456122#M667622</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Post the log level 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post the config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Jul 2010 20:10:06 GMT</pubDate>
    <dc:creator>Diego Armando Cambronero Arias</dc:creator>
    <dc:date>2010-07-29T20:10:06Z</dc:date>
    <item>
      <title>asa&amp;gre</title>
      <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456115#M667524</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I have problems with an ASA 5510 and GRE.&lt;/P&gt;&lt;P&gt;I can't make a gre tunnel from the inside network to a host on the internet. I only get to the part where I have to enter the username and password and there it breaks. I get a teardown gre connection in the logs exactly after 30 sec.&lt;/P&gt;&lt;P&gt;The inside network and outside network both have real ip addresses so I have no NAT configured and no need for NAT.&lt;/P&gt;&lt;P&gt;I tried fixup protocol pptp 1723 and inspect pptp.&lt;/P&gt;&lt;P&gt;The ACLs allow both gre and tcp 1723 both on the outside and on the inside (I also tried with allow ip any any to be sure it's not ACL related).&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:18:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456115#M667524</guid>
      <dc:creator>sergiu.campian</dc:creator>
      <dc:date>2019-03-11T18:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: asa&amp;gre</title>
      <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456116#M667533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please post the output of "show service-policy" and "show asp drop"&lt;/P&gt;&lt;P&gt;commands? Please follow below steps before collecting the output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Clear the counters i.e. clear service-policy &amp;amp; clear asp drop&lt;/P&gt;&lt;P&gt;-- Initiate a GRE tunnel session&lt;/P&gt;&lt;P&gt;-- Once it fails, issue "show service-policy" and "show asp drop"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 14:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456116#M667533</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-29T14:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: asa&amp;gre</title>
      <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456117#M667537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Thanks for the reply. Here is the output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show service-policy"&lt;/P&gt;&lt;P&gt;Global policy: &lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns preset_dns_map, packet 743, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225 _default_h323_map, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras _default_h323_map, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rtsp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: esmtp _default_esmtp_map, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny , packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip , packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 3, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ip-options _default_ip_options_map, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: pptp, packet 14, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;Interface inside10:&lt;BR /&gt;&amp;nbsp; Service-policy: inside10-policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inside10-class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS: card status Up, mode inline fail-open, sensor vs0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; packet input 0, packet output 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;Interface outside:&lt;BR /&gt;&amp;nbsp; Service-policy: pptp_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: pptp-port&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: pptp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: outside-class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS: card status Up, mode inline fail-open, sensor vs0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; packet input 0, packet output 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Result of the command: "show asp drop"&lt;/P&gt;&lt;P&gt;Frame drop:&lt;BR /&gt;&amp;nbsp; First TCP packet not SYN (tcp-not-syn)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 145&lt;BR /&gt;&amp;nbsp; TCP failed 3 way handshake (tcp-3whs-failed)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&lt;BR /&gt;&amp;nbsp; TCP RST/FIN out of order (tcp-rstfin-ooo)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&lt;BR /&gt;&amp;nbsp; Dropped pending packets in a closed socket (np-socket-closed)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;Last clearing: 17:29:07 EEDT Jul 29 2010 by enable_15&lt;/P&gt;&lt;P&gt;Flow drop:&lt;/P&gt;&lt;P&gt;Last clearing: 17:29:07 EEDT Jul 29 2010 by enable_15&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 14:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456117#M667537</guid>
      <dc:creator>sergiu.campian</dc:creator>
      <dc:date>2010-07-29T14:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: asa&amp;gre</title>
      <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456118#M667550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see that you have an IPS module installed on the firewall. Can you bypass&lt;/P&gt;&lt;P&gt;the IPS module for the PPTP traffic and see if that helps? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 14:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456118#M667550</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-29T14:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: asa&amp;gre</title>
      <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456119#M667557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I bypassed the IPS for all the traffic with the same result &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 14:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456119#M667557</guid>
      <dc:creator>sergiu.campian</dc:creator>
      <dc:date>2010-07-29T14:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: asa&amp;gre</title>
      <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456120#M667579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you collect some captures on the inside and outside of ASA, so that we can see where it is failing&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;also have you tried bypassing the firewall does it work fine (just to confirm that the configuration is fine)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any way the captures on ASA's inside and outside will tell us who and hopefully why the device is dropping the packet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 16:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456120#M667579</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-07-29T16:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: asa&amp;gre</title>
      <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456121#M667600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the code version you are running on the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 17:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456121#M667600</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-29T17:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: asa&amp;gre</title>
      <link>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456122#M667622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Post the log level 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post the config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 20:10:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-gre/m-p/1456122#M667622</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-07-29T20:10:06Z</dc:date>
    </item>
  </channel>
</rss>

