<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inspection Issues with 12.4 T Code Versions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295738#M825429</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what is the TAC case#?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Oct 2009 03:09:39 GMT</pubDate>
    <dc:creator>sadsiddi</dc:creator>
    <dc:date>2009-10-08T03:09:39Z</dc:date>
    <item>
      <title>Inspection Issues with 12.4 T Code Versions</title>
      <link>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295736#M825418</link>
      <description>&lt;P&gt;We are in the process of looking for a code to begin ZBF implementation.  Currently we have tried about 4 versions of 12.4 T code lines and have encountered the same issue each time.  If we have two subnets configured on the same interface, with inspection enabled, the subnets are unable to communicate with each other.  The following errors are seen in the inspect drop log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct  6 2009 20:29:34 CDT: %FW-6-DROP_PKT: Dropping tcp session 10.32.120.213:3671 170.211.162.3:524  due to  Invalid Segment with ip ident 61659 tcpflags 0x5010 seq.no 2534202883 ack 3333181490&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have been working with TAC and so far have been unable to identify a specific bug.  We have tried older and the latest IOS versions.  The only workaround is to disable inspection, but prefer not to do that.  Anyone else encountered this or have identified a specific bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295736#M825418</guid>
      <dc:creator>kenneth.rogers</dc:creator>
      <dc:date>2019-03-11T16:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Inspection Issues with 12.4 T Code Versions</title>
      <link>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295737#M825425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What other codes did you try? What inspections do you have enabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same syslog would have a little more information in 12.4(24)T&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried 15.0.1M? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to collect captures on both sides to see if packets arrive out of order if so, it could be due to CSCtc40876 and 15.0.1M would have the fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Oct 2009 23:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295737#M825425</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-10-07T23:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Inspection Issues with 12.4 T Code Versions</title>
      <link>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295738#M825429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what is the TAC case#?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Oct 2009 03:09:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295738#M825429</guid>
      <dc:creator>sadsiddi</dc:creator>
      <dc:date>2009-10-08T03:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Inspection Issues with 12.4 T Code Versions</title>
      <link>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295739#M825431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The images we have tried are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c1841-adventerprisek9-mz.124-&lt;/P&gt;&lt;P&gt;22.T3.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c1841-adventerprisek9-mz.124-24.T.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c1841-adventerprisek9-mz.124-20.T4.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also experienced the same with a 2811 router running c2800nm-advipservicesk9-mz.124-15.T9 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are inspecting the following:&lt;/P&gt;&lt;P&gt;tcp&lt;/P&gt;&lt;P&gt; udp&lt;/P&gt;&lt;P&gt;  ftp&lt;/P&gt;&lt;P&gt;  smtp&lt;/P&gt;&lt;P&gt;  rcmd&lt;/P&gt;&lt;P&gt;  vdolive&lt;/P&gt;&lt;P&gt;  streamworks&lt;/P&gt;&lt;P&gt;  rtsp&lt;/P&gt;&lt;P&gt;  cuseeme&lt;/P&gt;&lt;P&gt;  netshow&lt;/P&gt;&lt;P&gt;  msrpc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tried any additional codes or conducted any packet captures due to disturbing a production site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our TAC case is 612538115.  Please do not think I am trying to by-pass TAC as our engineer is doing an excellent job as always in researching this.  I just want to see if anyone else out there has encountered this. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Oct 2009 14:00:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295739#M825431</guid>
      <dc:creator>kenneth.rogers</dc:creator>
      <dc:date>2009-10-08T14:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Inspection Issues with 12.4 T Code Versions</title>
      <link>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295740#M825433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Best option is to try with minimum inspections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp&lt;/P&gt;&lt;P&gt;udp&lt;/P&gt;&lt;P&gt;ftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ropping tcp session 10.32.120.213:3671 170.211.162.3:524 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What application is this listening on port 524? Is this Novell Core Portocol?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you enable the FW, do http, smtp and other commonly used protol work? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem is only with tcp 524?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like your TAC engineer already mentioned this may be due to asymmetry in routing. To verify this, we need packets captures before and after the router so, we can compare the seq. numbers and ack. numbers and also look at the syslog message and figure out why the FW may be dropping these packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Oct 2009 21:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspection-issues-with-12-4-t-code-versions/m-p/1295740#M825433</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-10-11T21:27:35Z</dc:date>
    </item>
  </channel>
</rss>

