<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5505 and tcp connections drops.? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480080#M733057</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great!&lt;/P&gt;&lt;P&gt;Can you see if you're getting logs related to this connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Jun 2010 16:13:32 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2010-06-11T16:13:32Z</dc:date>
    <item>
      <title>ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480072#M733036</link>
      <description>&lt;P&gt;Hi there. I have a strange issue.&lt;/P&gt;&lt;P&gt;I have a ASA 5505 with some clients behind it who connects to an offsite database.&lt;/P&gt;&lt;P&gt;They run the application all day, but for longer periods of times, ie 1-2 hours they are idle in the application.&lt;/P&gt;&lt;P&gt;When they start using the application again they get messaages that they have been disconnected from the databse or they get an unresponsive&lt;/P&gt;&lt;P&gt;applications for like 5-10 minutes beforeit starts to function again.&lt;/P&gt;&lt;P&gt;To solve this I thought I increase the tcp timeout so I did, for the client server traffic. Now it's set to 4 hrs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT I still get the error.??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone got a clue what could cause this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Joel&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480072#M733036</guid>
      <dc:creator>j-tagesson</dc:creator>
      <dc:date>2019-03-11T17:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480073#M733038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Isn't the application itself where the're getting disconnected at?&lt;/P&gt;&lt;P&gt;I don't think they are being disconnected by the ASA if you increased the TCP timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know if the PING works all the time (even when they are disconnected)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just want to know if the issue is that the connection is being torn down by the ASA or that the application itself disconnects the users after an idle period.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 14:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480073#M733038</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-10T14:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480074#M733041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good thinking.&lt;/P&gt;&lt;P&gt;I was thinking that my new 4 hrs tcp timeout sh conn would work as proof that It's not the ASA firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meanwhile the server guys put a client outside the firewall...&lt;/P&gt;&lt;P&gt;And that client haven't had the disconnect issue..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I guess the problem came right back at us. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Ping works all the time btw.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 14:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480074#M733041</guid>
      <dc:creator>j-tagesson</dc:creator>
      <dc:date>2010-06-10T14:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480075#M733043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mmm...&lt;/P&gt;&lt;P&gt;If the ASA is causing the problem, then it should show in the logs.&lt;/P&gt;&lt;P&gt;Can you post the logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 14:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480075#M733043</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-10T14:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480076#M733045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's where it's getting tricky.. I can't seem to find anything in the logs. I have set up a syslog server but either I have set up the logging wrong or&lt;/P&gt;&lt;P&gt;it doesn't show any error..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance, I get&amp;nbsp; local1.warning and local1.notice but I can't find any errors regarding this communication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my logging: (attatched file)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I doing something wrong ?&lt;/P&gt;&lt;P&gt;Also, I have logging informational on the rule with the traffic from client to server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 14:56:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480076#M733045</guid>
      <dc:creator>j-tagesson</dc:creator>
      <dc:date>2010-06-10T14:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480077#M733047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're not getting any logs on the syslog server?&lt;/P&gt;&lt;P&gt;Can you change it to level debugging?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 15:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480077#M733047</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-10T15:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480078#M733050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry. I'm getting logs to syslog , jut not anything interesting with the ipadresses that I've specified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can change it to debugging and se if anything happends..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jun 2010 07:12:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480078#M733050</guid>
      <dc:creator>j-tagesson</dc:creator>
      <dc:date>2010-06-11T07:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480079#M733053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found out that I had to enable 106100 messages which by default didn't get logged to syslog.. Now I'm getting my traffic sent to the syslog server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jun 2010 07:45:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480079#M733053</guid>
      <dc:creator>j-tagesson</dc:creator>
      <dc:date>2010-06-11T07:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480080#M733057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great!&lt;/P&gt;&lt;P&gt;Can you see if you're getting logs related to this connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jun 2010 16:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480080#M733057</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-11T16:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480081#M733060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you solve this? I'm having the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jul 2010 09:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480081#M733060</guid>
      <dc:creator>rcordeiro</dc:creator>
      <dc:date>2010-07-08T09:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480082#M733061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same problem on my end. Only thing I can see is when the connection drops, I get this logged:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6&amp;nbsp;&amp;nbsp;&amp;nbsp; Jul 29 2010&amp;nbsp;&amp;nbsp;&amp;nbsp; 16:47:56&amp;nbsp;&amp;nbsp;&amp;nbsp; 302014&amp;nbsp;&amp;nbsp;&amp;nbsp; 99.100.154.220&amp;nbsp;&amp;nbsp;&amp;nbsp; 3389&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.20.12.214&amp;nbsp;&amp;nbsp;&amp;nbsp; 9261&amp;nbsp;&amp;nbsp;&amp;nbsp; Teardown TCP connection 49927 for outside:99.100.154.220/3389 to inside:10.20.12.214/9261 duration 0:13:39 bytes 3083949 TCP Reset-I&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that's the only indicator I have of anything going wrong on this, and that's when it drops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My configuration is all but virgin - no funky ACL's - just base implied allows&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 23:53:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480082#M733061</guid>
      <dc:creator>Michichael</dc:creator>
      <dc:date>2010-07-29T23:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480083#M733062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem was with connections to a database, if the connections reached the idle limit the firewall closes the connection and next time someone did something on the appliacation.&lt;/P&gt;&lt;P&gt;I solved this creating a "Service Application Rule" with a ACL to the interesting traffic and defining 5 hours for the connection timeout (if someone leave the application idle for more than 5 hour it could easily restart it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rui Cordeiro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jul 2010 09:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480083#M733062</guid>
      <dc:creator>rcordeiro</dc:creator>
      <dc:date>2010-07-30T09:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 and tcp connections drops.?</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480084#M733063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;rcordeiro wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem was with connections to a database, if the connections reached the idle limit the firewall closes the connection and next time someone did something on the appliacation.&lt;/P&gt;&lt;P&gt;I solved this creating a "Service Application Rule" with a ACL to the interesting traffic and defining 5 hours for the connection timeout (if someone leave the application idle for more than 5 hour it could easily restart it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rui Cordeiro&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info Rui, unfortunately, I don't think this is the case here. I'll have to keep looking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This problem happens randomly - download a youtube video and it will just stop at a random point and you have to refresh the page. Do so and it might work, or might stop at a different point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remote desktop to my home server, same thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The connections die with a RESET-I logged, but I don't see any reason for the reset.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jul 2010 15:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-and-tcp-connections-drops/m-p/1480084#M733063</guid>
      <dc:creator>Michichael</dc:creator>
      <dc:date>2010-07-30T15:54:22Z</dc:date>
    </item>
  </channel>
</rss>

