<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: traffic not passing through firewall at sometimes for some u in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426199#M730031</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;The information was useful&lt;/P&gt;&lt;P&gt;Will check that......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Arulkumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Feb 2010 06:11:53 GMT</pubDate>
    <dc:creator>arulkumar80</dc:creator>
    <dc:date>2010-02-22T06:11:53Z</dc:date>
    <item>
      <title>traffic not passing through firewall at sometimes for some users</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426195#M730027</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Most of the time everything works fine on the firewall and all the required traffic is passing through the firewall as expected by the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes some of the users are not able to a)go online, b)access&amp;nbsp; the servers.&lt;/P&gt;&lt;P&gt;the users&amp;nbsp; facing this issue are able to work with the existing connections but if they try to open a new connection to any servers they fail.&lt;/P&gt;&lt;P&gt;At that time users are not able to go online either. I am able to ping that time but i am not able to telnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;servers are in one security level and users are in different security level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they user remove the lan cable and refix it everthing works normal for that user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Arulkumar&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426195#M730027</guid>
      <dc:creator>arulkumar80</dc:creator>
      <dc:date>2019-03-11T17:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not passing through firewall at sometimes for some u</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426196#M730028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't have any logs from the time when the problem happened?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you reaching the limit of connections permitted?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Feb 2010 20:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426196#M730028</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-02-20T20:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not passing through firewall at sometimes for some u</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426197#M730029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't have any logs from the time when the problem happened?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you reaching the limit of connections permitted?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;How can i check if ASA is reaching the limit of connections permitted. (any command to check that)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Arulkumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Feb 2010 08:49:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426197#M730029</guid>
      <dc:creator>arulkumar80</dc:creator>
      <dc:date>2010-02-21T08:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not passing through firewall at sometimes for some u</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426198#M730030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The ''show conn count'' will show you amount of connections at a certain point, you can compare this number to the max. connections that your specific model can handle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, for the servers, they have a limit on the amount of embryonic connections and total connections as well on the STATIC command. (The same applies for dynamic NAT).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the problem is with the amount of traffic, a temporary solution is to change the timeouts for the XLATEs and connections:&amp;nbsp; ''sh run timeout''&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Feb 2010 14:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426198#M730030</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-02-21T14:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not passing through firewall at sometimes for some u</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426199#M730031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;The information was useful&lt;/P&gt;&lt;P&gt;Will check that......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Arulkumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Feb 2010 06:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426199#M730031</guid>
      <dc:creator>arulkumar80</dc:creator>
      <dc:date>2010-02-22T06:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not passing through firewall at sometimes for some u</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426200#M730032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;from &lt;STRONG&gt;sh conn&lt;/STRONG&gt; i see that device can handle more number of connection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;will reducing the timeout for xlate and connection work?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;because the only some of the hosts are not able to connect to a servers or go online and it is happening sometimes only sometimes &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;after few minutes the hosts are able to connect to severs and go online normally.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;when the issue is occuring ping works fine&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;and if the host"s lan cable is unlugged and relugged back the issue is resolved, they are able to connect to servers an able to go online.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Servers are connected in 1 interface and internet is on another interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;hope my explanation is clear.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Your help is much appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Arulkumar&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Feb 2010 14:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426200#M730032</guid>
      <dc:creator>arulkumar80</dc:creator>
      <dc:date>2010-02-22T14:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not passing through firewall at sometimes for some u</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426201#M730034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will be a good test to try lowering the timeouts for the translation and connections...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just make sure, the XLATE timeout should be greater than the CONN timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's see the results...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Feb 2010 21:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426201#M730034</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-02-22T21:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not passing through firewall at sometimes for some u</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426202#M730036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;tried lowering the timeouts for the translation and connections, no good....&lt;/P&gt;&lt;P&gt;please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Arulkumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 05:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426202#M730036</guid>
      <dc:creator>arulkumar80</dc:creator>
      <dc:date>2010-02-26T05:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not passing through firewall at sometimes for some u</title>
      <link>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426203#M730037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arulkumar,&lt;/P&gt;&lt;P&gt;We just can't manipulate the timeout not knowing what the cause it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do the logs say when these hosts can't go out?&lt;/P&gt;&lt;P&gt;Can they ping the firewall's IP address?&lt;/P&gt;&lt;P&gt;Can they get name resolution when they ping yahoo.com or google.com&lt;/P&gt;&lt;P&gt;Can they load the page by IP address and not name?&lt;/P&gt;&lt;P&gt;Can they ping an outside IP through the firewall?&lt;/P&gt;&lt;P&gt;Only TCP breaks? ICMP works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable logging on the firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;logging buffered 7&lt;/P&gt;&lt;P&gt;sh logg | i x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where x.x.x.x is the host that cannot got out. Explain what protocol (http ?) breaks. You are trying a telent x.x.x.x 80 to verify?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 13:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-not-passing-through-firewall-at-sometimes-for-some-users/m-p/1426203#M730037</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-02-26T13:58:08Z</dc:date>
    </item>
  </channel>
</rss>

