<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ZBF sometimes blocking websites in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456097#M689558</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:ben.williams@dhi.co.uk"&gt;ben.williams@dhi.co.uk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to be having the same problem on my 1941W.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;The odd site here and there is dropped, refresh the page returns to normal for a few more clicks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I can see incoming http packets being dropped by the OUTSIDE to INSIDE zone but can narrow it down to why this is happening.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Could this be a Dialer MTU or some timeout issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any reproducible situation? Everything else is just guessing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It *could* be a tcp-timeout if the application (browser) is not sending data, while users are reading a page.&lt;/P&gt;&lt;P&gt;This happens, when the browser is using&amp;nbsp; single-connect, sending multiple requests through the same session instead of opening a new tcp for each page element resp. request. This is the deafult behaviour for modern browsers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible, make a packet dump from the browser session and compare how it behaves. If you have good timestamps you can even correlate with the IOS debug messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least that would be my approach.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds, MiKa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Nov 2010 23:44:40 GMT</pubDate>
    <dc:creator>m.kafka</dc:creator>
    <dc:date>2010-11-02T23:44:40Z</dc:date>
    <item>
      <title>ZBF sometimes blocking websites</title>
      <link>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456094#M689523</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ZBF configuration on a Cisco 3825 is sometimes blocking websites, but not always. Lets say users browse to Linkedin.com, they click around on the website, accessing several pages and then suddenly they get the IE error saying that the website is unavailable. This is what appears in my ZBF log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;028454: May 25 07:49:48.360 CET: %FW-6-DROP_PKT: Dropping tcp session 64.74.98.80:80 INSIDEIP:49748 on zone-pair OUTSIDE_INSIDE_ZP class class-default due to&amp;nbsp; DROP action found in policy-map with ip ident 0 &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;028455: May 25 07:50:22.553 CET: %FW-6-LOG_SUMMARY: 5 packets were dropped from 64.74.98.80:80 =&amp;gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;INSIDEIP:49748 (target:class)-(OUTSIDE_INSIDE_ZP:class-default)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;028456: May 25 07:50:43.677 CET: %FW-6-DROP_PKT: Dropping tcp session 64.74.98.80:80 INSIDEIP:49750 on zone-pair OUTSIDE_INSIDE_ZP class class-default due to&amp;nbsp; DROP action found in policy-map with ip ident 0 &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;028457: May 25 07:51:21.214 CET: %FW-6-DROP_PKT: Dropping tcp session 64.74.98.80:80 INSIDEIP:49754 on zone-pair OUTSIDE_INSIDE_ZP class class-default due to&amp;nbsp; DROP action found in policy-map with ip ident 0 &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;028458: May 25 07:51:22.554 CET: %FW-6-LOG_SUMMARY: 3 packets were dropped from 64.74.98.80:80 =&amp;gt; INSIDEIP:49750 (target:class)-(OUTSIDE_INSIDE_ZP:class-default)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;028459: May 25 07:51:22.554 CET: %FW-6-LOG_SUMMARY: 4 packets were dropped from 64.74.98.80:80 =&amp;gt; INSIDEIP:49754 (target:class)-(OUTSIDE_INSIDE_ZP:class-default)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packets are being dropped on the OUTSIDE -&amp;gt; INSIDE policy because for some reason they have not been inspected by the INSIDE -&amp;gt; OUTSIDE policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my ZBF config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;policy-map type inspect INSIDE_OUTSIDE_PM&lt;BR /&gt;class type inspect P2P_CM&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;class type inspect HTTP_URLFILTER_CM&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt;&amp;nbsp; service-policy urlfilter WEBSENSE_PM&lt;BR /&gt;class type inspect COMMON_PROTOCOLS_CM&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt;class type inspect TCP_UDP_ICMP_CM&lt;BR /&gt;&amp;nbsp; inspect &lt;BR /&gt;class class-default&lt;BR /&gt;&amp;nbsp; drop log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;class-map type inspect match-all HTTP_URLFILTER_CM&lt;BR /&gt;match protocol http&lt;BR /&gt;match access-group name HTTP_URLFILTER_ACL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;ip access-list extended HTTP_URLFILTER_ACL&lt;BR /&gt;permit ip any any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;policy-map type inspect urlfilter WEBSENSE_PM&lt;BR /&gt;parameter type urlfpolicy websense WEBSENSE_SERVER_PARMAP&lt;BR /&gt;class type urlfilter websense WEBSENSE_CM&lt;BR /&gt;&amp;nbsp; server-specified-action&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me why this happens sometimes? It happend also before implementing Websense so I dont think that thats the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456094#M689523</guid>
      <dc:creator>TCC Service</dc:creator>
      <dc:date>2019-03-11T17:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: ZBF sometimes blocking websites</title>
      <link>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456095#M689534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;The dropped packets are hitting the class-map default of the &lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; "&gt;OUTSIDE_INSIDE_ZP which means they cannot be mapped to sessions which were established through the policy map of the INSIDE_OUTSIDE_ZP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any other security devices like IDS/IPS that either might drop packets or send tcp-resets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try&lt;/P&gt;&lt;P&gt;&lt;STRONG class="cCN_CmdName"&gt;show policy-map type inspect zone-pair&lt;/STRONG&gt; [&lt;EM class="cArgument"&gt;zone-pair-name&lt;/EM&gt;] [&lt;STRONG class="cKeyword"&gt;sessions&lt;/STRONG&gt;] to verify that the inspection might have dropped the session.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 May 2010 19:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456095#M689534</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2010-05-25T19:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: ZBF sometimes blocking websites</title>
      <link>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456096#M689544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to be having the same problem on my 1941W.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;The odd site here and there is dropped, refresh the page returns to normal for a few more clicks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I can see incoming http packets being dropped by the OUTSIDE to INSIDE zone but can narrow it down to why this is happening.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Could this be a Dialer MTU or some timeout issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 14:18:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456096#M689544</guid>
      <dc:creator>Ben Williams</dc:creator>
      <dc:date>2010-11-02T14:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: ZBF sometimes blocking websites</title>
      <link>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456097#M689558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:ben.williams@dhi.co.uk"&gt;ben.williams@dhi.co.uk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to be having the same problem on my 1941W.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;The odd site here and there is dropped, refresh the page returns to normal for a few more clicks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I can see incoming http packets being dropped by the OUTSIDE to INSIDE zone but can narrow it down to why this is happening.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Could this be a Dialer MTU or some timeout issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any reproducible situation? Everything else is just guessing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It *could* be a tcp-timeout if the application (browser) is not sending data, while users are reading a page.&lt;/P&gt;&lt;P&gt;This happens, when the browser is using&amp;nbsp; single-connect, sending multiple requests through the same session instead of opening a new tcp for each page element resp. request. This is the deafult behaviour for modern browsers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible, make a packet dump from the browser session and compare how it behaves. If you have good timestamps you can even correlate with the IOS debug messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least that would be my approach.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds, MiKa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 23:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456097#M689558</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2010-11-02T23:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: ZBF sometimes blocking websites</title>
      <link>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456098#M689576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems to be something to do with the Trend Content Filter poicy thats added to the IN to OUT zone pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a test recionfigured the router from the begining, all working fine until I added the content filter policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Web sites start to droping at incomming packets for no reason as the sites are no part of the content filter policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have logged a support call with Cisco who seem abit stumped on the matter, could be a Bug in the IOS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 17:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456098#M689576</guid>
      <dc:creator>Ben Williams</dc:creator>
      <dc:date>2010-11-09T17:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: ZBF sometimes blocking websites</title>
      <link>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456099#M689587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Updated the IOS to c1900-universalk9-mz.SPA.150-1.M4 from .M1 seems to be working ok just very slow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 09:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-sometimes-blocking-websites/m-p/1456099#M689587</guid>
      <dc:creator>Ben Williams</dc:creator>
      <dc:date>2010-11-19T09:30:13Z</dc:date>
    </item>
  </channel>
</rss>

