<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Flow closed by inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481836#M739406</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont believe http traffic is being inspected...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cust-vpn-fw01# show run policy-map&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map External-policy&lt;BR /&gt; class External-class&lt;BR /&gt;&amp;nbsp; inspect icmp error &lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; flow-export event-type all destination 172.29.0.158&lt;BR /&gt;!&lt;BR /&gt;cust-vpn-fw01# show service-policy&lt;/P&gt;&lt;P&gt;Global policy: &lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;/P&gt;&lt;P&gt;Interface External:&lt;BR /&gt;&amp;nbsp; Service-policy: External-policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: External-class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: icmp error, packet 0, drop 0, reset-drop 0&lt;BR /&gt;cust-vpn-fw01#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Aug 2010 23:03:56 GMT</pubDate>
    <dc:creator>bgl-group</dc:creator>
    <dc:date>2010-08-13T23:03:56Z</dc:date>
    <item>
      <title>Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481832#M739394</link>
      <description>&lt;P&gt;I have a problem with a customer trying to reach a server pbo-prd01 in our network over a VPN from ip address 'cust-prd01'where the packets seem to be dropped by 'Flow closed by inspection' &lt;BR /&gt;What does this mean and how can i fix it?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The IPS sensor in the firewall is switched off.&lt;/P&gt;&lt;P&gt;cust-prd01 18580 pbo-prd01 1860 Teardown TCP connection 17266 for External:cust-prd01/18580 to Inside:pbo-prd01/1860 duration 0:00:08 bytes 11007 Flow closed by inspection&amp;nbsp; &lt;BR /&gt;cust-prd01 18580 pbo-prd01 1861 Teardown TCP connection 17268 for External:cust-prd01/18580 to Inside:pbo-prd01/1861 duration 0:00:07 bytes 8847 Flow closed by inspection&lt;BR /&gt;cust-prd01 18580 pbo-prd01 1862 Teardown TCP connection 17270 for External:cust-prd01/18580 to Inside:pbo-prd01/1862 duration 0:00:06 bytes 8393 Flow closed by inspection&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:25:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481832#M739394</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2019-03-11T18:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481833#M739396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of traffic you are sending between the client and the server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 22:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481833#M739396</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-13T22:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481834#M739400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, thanks for the reply. It's XML data in the packets.&lt;/P&gt;&lt;P&gt;The IOS is v8.2(2)4&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 22:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481834#M739400</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2010-08-13T22:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481835#M739402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you inspecting the http traffic? Can you post the output of "show run&lt;/P&gt;&lt;P&gt;policy-map" and "show service-policy" commands?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 23:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481835#M739402</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-13T23:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481836#M739406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont believe http traffic is being inspected...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cust-vpn-fw01# show run policy-map&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map External-policy&lt;BR /&gt; class External-class&lt;BR /&gt;&amp;nbsp; inspect icmp error &lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp; flow-export event-type all destination 172.29.0.158&lt;BR /&gt;!&lt;BR /&gt;cust-vpn-fw01# show service-policy&lt;/P&gt;&lt;P&gt;Global policy: &lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;/P&gt;&lt;P&gt;Interface External:&lt;BR /&gt;&amp;nbsp; Service-policy: External-policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: External-class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: icmp error, packet 0, drop 0, reset-drop 0&lt;BR /&gt;cust-vpn-fw01#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 23:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481836#M739406</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2010-08-13T23:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481837#M739410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have seen those kind of errors when the vpn that the traffic is going over drops, even for a second. When the tunnel goes down, the conns going over it are torn down and cite that reason. You could try adding the following two command to prevent the connection from being removed instantly:&amp;nbsp; Sysopt connection preserve-vpn-flows Sysopt connection reclassify-vpn&amp;nbsp;&amp;nbsp; The first one keep the connection if the tunnel drops and the second one re encrypts should the tunnels come back up.&amp;nbsp;&amp;nbsp; - Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 23:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481837#M739410</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-08-13T23:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481838#M739414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it affecting your traffic? If it is not affecting the traffic, you might&lt;/P&gt;&lt;P&gt;be hitting a bug where the ASA is generating the log message incorrectly&lt;/P&gt;&lt;P&gt;even when the flow is terminated normally. The bug ID is CSCtg17779.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 23:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481838#M739414</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-13T23:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481839#M739416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, traffic is being affected. I see the XML request leave but the return packet is dropped by this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pbo-prd03 2632 x.x.x.x 18580 Built outbound TCP connection 24127 for External:x.x.x.x/18580 (x.x.x.x/18580) to Inside:pbo-prd03/2632 (pbo-prd03-nat/2632)&lt;/P&gt;&lt;P&gt;x.x.x.x 18580 pbo-prd03 2632 Teardown TCP connection 24127 for External:x.x.x.x/18580 to Inside:pbo-prd03/2632 duration 0:00:04 bytes 9943 Flow closed by inspection&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 23:21:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481839#M739416</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2010-08-13T23:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481840#M739419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Magnus. I tried these commands but they didn't resolve the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 23:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481840#M739419</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2010-08-13T23:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481841#M739422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you sniff the traffic on your inside to see if the server is closing the&lt;/P&gt;&lt;P&gt;connection? If the server closes the connection via FIN or RST, the firewall&lt;/P&gt;&lt;P&gt;will also close the connection but due to the bug I have mentioned, it will&lt;/P&gt;&lt;P&gt;wrongly generate the "flow closed by inspection" message. As mentioned in&lt;/P&gt;&lt;P&gt;the bug, the flow will be terminated for other reasons (normal firewall&lt;/P&gt;&lt;P&gt;operations) but the error message will be different. The sniffer capture&lt;/P&gt;&lt;P&gt;will be useful in determining the root cause of the flow termination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 23:40:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481841#M739422</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-13T23:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481842#M739426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've run a wireshark trace on the firewall and the connection is closes down ok &lt;/P&gt;&lt;P&gt;internal server --&amp;gt; external server FIN,ACK.&lt;/P&gt;&lt;P&gt;external server --&amp;gt; internal server ACK&lt;/P&gt;&lt;P&gt;external server --&amp;gt; internal server FIN, ACK&lt;/P&gt;&lt;P&gt;internal server --&amp;gt; external server ACK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure it's that bug causing problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 00:00:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481842#M739426</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2010-08-14T00:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481843#M739429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, both devices exchange FIN/ACK indicating that they are done with data&lt;/P&gt;&lt;P&gt;transfer. This indicates to the firewall that the connection is no longer&lt;/P&gt;&lt;P&gt;needed and it can tear-down the connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 00:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481843#M739429</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-14T00:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481844#M739431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm I believe I have seen this issue before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think what is really happening is that the connection is timing out and so the inspection is closing due to timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I saw it, it was due to a policy-nat statement conflicting with the nat statement required, but the fact that your wireshark shows traffic hitting the server would seem to disprove this theory, perhaps something to check though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 00:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481844#M739431</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-08-14T00:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481845#M739436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All these seem to be very short lived (6,7 and 8 seconds) connections.&lt;/P&gt;&lt;P&gt;Issue this command and see what inspections are being hit and see if you can deny this flow from being inspected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh service-policy flow tcp ho cust-prd01 ho pbo-prd01 eq 1862&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 03:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481845#M739436</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-14T03:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481846#M739439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply...I dont have any policy-nats, only static nats.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 13:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481846#M739439</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2010-08-14T13:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481847#M739442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi I've tried this command but it just comes up blank, no stats.&lt;/P&gt;&lt;P&gt;Any other ideas? I cant see how a firewall configured with no inspection drops packets? Doesn't seem logical, but I def see packets leaving the external interface but getting dropped on the way back. Might have to open a TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 13:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481847#M739442</guid>
      <dc:creator>bgl-group</dc:creator>
      <dc:date>2010-08-14T13:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Flow closed by inspection</title>
      <link>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481848#M739444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In only see icmp error inspection configured.&amp;nbsp; Opening a TAC case sounds like a&lt;/P&gt;&lt;P&gt;good idea at this point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 13:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flow-closed-by-inspection/m-p/1481848#M739444</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-14T13:42:59Z</dc:date>
    </item>
  </channel>
</rss>

