<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stateful Inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326601#M764228</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I'll try that.  One other question.  I was looking on Cisco.com and found some sample configs, and they all had the inspect on the inside interface coming in to it.  Is this a preferred method, as opposed to having it on the outside going out?  Also, if the router is setup as a DNS server, what is required to let the dns replys back in, I kept seeing drops of udp(53).  I had to change the workstation to use the dns server directly instead of relaying through the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Oct 2009 13:36:04 GMT</pubDate>
    <dc:creator>bdedek</dc:creator>
    <dc:date>2009-10-29T13:36:04Z</dc:date>
    <item>
      <title>Stateful Inspection</title>
      <link>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326599#M764226</link>
      <description>&lt;P&gt;I have a lab setup with a 1721 connected to the Internet.  I have enabled ip inspection with several engines including http and https, on the outside interface out bound.  I also have an access list on the outside interface blocking inbound traffic.  It seems that recently I discovered that when trying to download from Rapidshare and Hotfile sites, the download begins and then hangs pretty quickly.   I have confirmed that if I disable the ip inspect out and the ip access group in, the downloads work as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also checked the logs and don't see any denys so I can't figure why the connection gets dropped.  Is there any other debugs that might lead me to find the problem?  I have never had this issue until recently, so I don't know if Rapidshare and other providers have changed something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help you may provide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326599#M764226</guid>
      <dc:creator>bdedek</dc:creator>
      <dc:date>2019-03-11T16:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection</title>
      <link>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326600#M764227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep the inspections to the minimum required and see if that helps.&lt;/P&gt;&lt;P&gt;inspect only tcp, udp, icmp and ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leave the acl applied IN on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable "ip inspect log drop" and watch the logs and see if the FW is dropping the packets for some reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Oct 2009 04:00:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326600#M764227</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-10-29T04:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection</title>
      <link>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326601#M764228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I'll try that.  One other question.  I was looking on Cisco.com and found some sample configs, and they all had the inspect on the inside interface coming in to it.  Is this a preferred method, as opposed to having it on the outside going out?  Also, if the router is setup as a DNS server, what is required to let the dns replys back in, I kept seeing drops of udp(53).  I had to change the workstation to use the dns server directly instead of relaying through the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Oct 2009 13:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326601#M764228</guid>
      <dc:creator>bdedek</dc:creator>
      <dc:date>2009-10-29T13:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection</title>
      <link>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326602#M764229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the first question there is no difference. You can inspect out on the outside or in on the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the later, depending on the IOS version you can do inspect udp or inspect dns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Oct 2009 16:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stateful-inspection/m-p/1326602#M764229</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-10-29T16:47:04Z</dc:date>
    </item>
  </channel>
</rss>

