<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL not opening ...via PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466163#M856545</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, you can not do MPF on version 6.3 pix code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you are interested in upgrading to later version of the pix code, then definitely you can consider doing that instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Aug 2010 20:42:25 GMT</pubDate>
    <dc:creator>edadios</dc:creator>
    <dc:date>2010-08-16T20:42:25Z</dc:date>
    <item>
      <title>URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466145#M856489</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have one https ulr of one of our customer...which is not opening from office... This URL is hosted over internet...&lt;/P&gt;&lt;P&gt;Normally we open url in two way...via enabling proxy &amp;amp; other is disabling proxy (just to following diff paths).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access using any of above method does the patting over PIX 535 firewall (different pat)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This https url is not opening from Windows 7 Machines using without proxy.... but using proxy it opens.&lt;/P&gt;&lt;P&gt;However doing without proxy we can able to telnet to destination over port 443. that confirms we have necessry access from our source --pix to destination..&lt;/P&gt;&lt;P&gt; but still web open is not opening...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes from Win XP you use any method this url opens....&lt;/P&gt;&lt;P&gt;Win 7 from outside office net / other office where we have ASA firewall it opens..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is their anythig to do with PIX...../ any method to drill this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please guide..&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466145#M856489</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2019-03-11T18:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466146#M856492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Reading the problem description, if you are able to telnet on port 443 without the proxy from windows 7 PC outbound via the PIX firewall, that proves that there is nothing within the PIX firewall that is causing the issue that you are experiencing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest that you try different browser with your testing if you were using IE for testing (eg: Opera, Mozilla, Google Crome).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 07:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466146#M856492</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-12T07:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466147#M856497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for reply...we tried with many other browers too...&lt;/P&gt;&lt;P&gt;but still the issue is same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is only happing with win 7 in our office...but in our other office this is not a issue.&lt;/P&gt;&lt;P&gt;only difference is they have asa instead of PIX...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please guide...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 08:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466147#M856497</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-12T08:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466148#M856500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might want to try disabling the http inspection on the PIX and see if you still have the issue. What version of PIX are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 08:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466148#M856500</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-12T08:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466149#M856503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; PIX Version is 6.3(5)....&lt;/P&gt;&lt;P&gt;destination site it https...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;still will it help? can u provide url which will help to understand it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also in our pix i dont see fix up for https...fixup protocol https 443 will help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;BR /&gt;fixup protocol ftp 21&lt;BR /&gt;fixup protocol h323 h225 1720&lt;BR /&gt;fixup protocol h323 ras 1718-1719&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;fixup protocol http 80&lt;BR /&gt;fixup protocol rsh 514&lt;BR /&gt;fixup protocol rtsp 554&lt;BR /&gt;fixup protocol sip 5060&lt;BR /&gt;fixup protocol sip udp 5060&lt;BR /&gt;fixup protocol skinny 2000&lt;BR /&gt;no fixup protocol smtp 25&lt;BR /&gt;fixup protocol sqlnet 1521&lt;BR /&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;advise...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 08:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466149#M856503</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-12T08:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466150#M856507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds strange that it works through Proxy, but it doesn't work through browser directly.&lt;/P&gt;&lt;P&gt;No, there is no inspection for https, only for http, so it doesn't apply in your case.&lt;/P&gt;&lt;P&gt;What did you get when you are trying to browse the website directly (which error code)? and if you bring this very same Windows 7 host outside the network, it works fine?&lt;/P&gt;&lt;P&gt;Is the Windows 7 host in the same subnet/directly connected to the PIX interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 08:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466150#M856507</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-12T08:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466151#M856510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tried connecting same win 7 system, outside of firewall &amp;amp; it worked very well..&lt;/P&gt;&lt;P&gt;Please find the attached screen...when it fails to open the web page..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;error 1 . Internet connection has been lost&amp;nbsp;&amp;nbsp; -&amp;nbsp; (it can not be because at same time telnet to destination keeps on)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp; The Website is temperorily unavailable ...(at same time from another win 7 system with proxy it is working)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.&amp;nbsp; DNS not reachable&amp;nbsp;&amp;nbsp; (but we are able to resovled the name)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Last option of TLS &amp;amp; SSL has been already tried.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise how we can isolate this issue...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 09:28:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466151#M856510</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-12T09:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466152#M856514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might want to take a packet capture on the PIX inside and outside interfaces when you are trying to browse that website, and download the packet capture in pcap format to further review where it's failing.&lt;/P&gt;&lt;P&gt;PIX version 6.3.5 is pretty old version of code and it's already EOL, so potentially there might be bug that cause that issue. Here is the EOL notification for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/end_of_life_notice_for_cisco_pix_sec_app_v63.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps2030/end_of_life_notice_for_cisco_pix_sec_app_v63.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might want to upgrade the PIX to the latest interim of 6.3.5 or even upgrade to higher version. Please also be advised that PIX hardware itself has also reached EOL, and the replacement is ASA firewall. Here is the list of all PIX related EOL notifications for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_eol_notices_list.html"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_eol_notices_list.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 12:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466152#M856514</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-12T12:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466153#M856517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd; font-family: trebuchet ms,geneva; "&gt;Thanks&amp;nbsp; &lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; Calibri&amp;quot;: ; "&gt;halijenn,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; background-color: #f8fafd; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;You are true , its older IOS , being win7 the new OS issue could not see anywhere &amp;amp; it could be bug with this IOS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; background-color: #f8fafd; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;one more thing we are trying to isolate this issue , that is with DNS , in all test inside our network w/o proxy we were using internal DNS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; background-color: #f8fafd; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;While using same machine from outside ,DNS settings were outside DNS....it could be the possibility that 1st level resoluation is happening but somewhere it is not responding..becuase TCP session is ok all the time...Will keep you posted on this test..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: trebuchet ms,geneva;"&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; background-color: #f8fafd; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;Anyways ,&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; background-color: #f8fafd; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;Can you please guide through packet capture in PIX &amp;amp; its downloading method...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; background-color: #f8fafd; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; background-color: #f8fafd; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;Yogesh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; background-color: #f8fafd; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-IN; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 13:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466153#M856517</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-12T13:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466154#M856522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here we go:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/c.html#wp1053548"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/c.html#wp1053548&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are going to configure ACL, then capture on the inside interface, the ACL should match the inside host ip address and the web server ip address, while capture on the outside interface would then match the PATed ip address towards the web server ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 13:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466154#M856522</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-12T13:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466155#M856524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more observation for this issue which is isolating the internet PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have one more site from where this link iw working w/o proxy....&amp;amp; it uses same internet PIX to throw traffic to Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology we have&amp;nbsp; for both sites are&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside LAN --&amp;gt;Corp ASA 5510 .---&amp;gt; Internet PIX ---&amp;gt; Interenet Routers ---&amp;gt; Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From Site W ..url is working (ASA5510 ver 8.2 (1) )&lt;/P&gt;&lt;P&gt;From Site K url is not working ....(ASA Version 7.2(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we tried to reach microsoft &amp;amp; as per microsoft Corp ASA is blocking some TLS packets due which it is not opening..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;advise how can we go ahead with this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 08:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466155#M856524</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-13T08:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466156#M856527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest that you try lowering the MSS value to 1300.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command: &lt;STRONG&gt;sysopt connection tcpmss 1300&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 23:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466156#M856527</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-14T23:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466157#M856530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried&amp;nbsp; but still it is not working...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is output taken from system, command prompt..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Users\194645&amp;gt;ping -f -l 1300 medimmune.mdsol.com&lt;/P&gt;&lt;P&gt;Pinging medimmune.mdsol.com [70.42.4.189] with 1300 bytes of data:&lt;BR /&gt;Packet needs to be fragmented but DF set.&lt;BR /&gt;Packet needs to be fragmented but DF set.&lt;BR /&gt;Packet needs to be fragmented but DF set.&lt;/P&gt;&lt;P&gt;Ping statistics for 70.42.4.189:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packets: Sent = 3, Received = 0, Lost = 3 (100% loss),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Users\194645&amp;gt;ping -f -l 1260 medimmune.mdsol.com&lt;/P&gt;&lt;P&gt;Pinging medimmune.mdsol.com [70.42.4.189] with 1260 bytes of data:&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;BR /&gt;Request timed out.&lt;/P&gt;&lt;P&gt;Ping statistics for 70.42.4.189:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tried with setting up 1260 still not worked..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where could be issue &amp;amp; how we can isolate the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Yogesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Aug 2010 07:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466157#M856530</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-15T07:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466158#M856532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1260 seems ok. May be 70.42.4.189 doesn't respond to icmp.&lt;/P&gt;&lt;P&gt;Pls. try to see if you can load the page with the mss set to 1260.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are unable to load, then post the syslogs for that connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Aug 2010 13:42:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466158#M856532</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-15T13:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466159#M856535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried mss 1260 but still unable to load page.&lt;/P&gt;&lt;P&gt;but i see following mtu on interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do i need to change the interface mtu?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Yogesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 08:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466159#M856535</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-16T08:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466160#M856538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #943634; font-size: 9pt; font-family: Trebuchet MS; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;Following log is recorded on sys log which says it is MTU fragmentation issue on firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Trebuchet MS&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: #943634; font-size: 9pt; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-size: 11.0pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Trebuchet MS&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: #943634; font-size: 9pt; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-size: 11.0pt;"&gt;&lt;EM&gt;Aug 16 2010 13:05:45: %ASA-4-419001: Dropping TCP packet from inside: Yogesh/63831 to outside:70.42.4.189/443, reason: MSS exceeded, MSS 256, data 536&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; color: #333333; font-size: 12pt; mso-fareast-language: EN-IN; mso-fareast-font-family: 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;As earlier posted , i have tried downgrading MSS to 1260 but still unable to upload page....&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;Also mention that physical interfaces are configured with 1500 MTU i think may be because of that MSS 1260 set by sysopt command is not taking effect...Please correct me if i am wrong here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;Now , we clear what issue is....Many Many thanks to this Forum..&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;I'll appreciate if you can guide how we can resolve this...&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;sysopt connection tcpmss 1300 &amp;amp; also tried sysopt connection tcpmss 1260 as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;Do we need to use MPF here? Please guide...now we are very close to our resolution..&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style=": ; mso-fareast-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; color: #000000; Trebuchet MS&amp;quot;: ; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; mso-bidi-font-style: italic; ,&amp;quot;: ; mso-fareast-font-family: 'Times New Roman'; "&gt;Yogesh&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 09:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466160#M856538</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-16T09:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466161#M856541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With pings of 1260 set for -f appearing to work, with no errors like "Packet needs&amp;nbsp; to be fragmented but DF set."&amp;nbsp; The mtu and mss settings should really be&amp;nbsp; close enough to that value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set the following on the pix:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;mtu inside 1260 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then your mss should be less and follow&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;sysopt connection tcpmss 1200&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Actually, according to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk870/tk877/tk880/technologies_tech_note09186a008011a218.shtml"&gt;http://www.cisco.com/en/US/tech/tk870/tk877/tk880/technologies_tech_note09186a008011a218.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should be an mss of around 1220, but just try lowering until you get what works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also continue monitoring your logs, as they give you further idea, as you have already indicated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If lowering the value still does not take, I suggest saving the configuration and reloading the firewall. Ensuring that you have mtu of 1260 or lower, and mss accordingly showing up after the reboot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully it help you&amp;nbsp; get the issue resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 10:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466161#M856541</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2010-08-16T10:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466162#M856542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml"&gt;https://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow this link and add the fix to allow mss-exceed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No need to change the MTU on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 12:58:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466162#M856542</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-16T12:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466163#M856545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, you can not do MPF on version 6.3 pix code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you are interested in upgrading to later version of the pix code, then definitely you can consider doing that instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 20:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466163#M856545</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2010-08-16T20:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: URL not opening ...via PIX</title>
      <link>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466164#M856547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Hello All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Finally we reached to resolution by applying MPF on outside interface of ASA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;Many thanks to every one, for posting valuables inputs to reach the resolution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;Now we are able to upload page successfully.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;I still have following queries; will appreciate if you can answer the same.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Q1. This behavior is observed only on ASA IOS 7.0 but not in Version 8.0.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Understand that the&lt;SPAN style="color: black;"&gt; 7.0 release introduces several new security enhancements, one of which is a check for TCP endpoints which adhere to the advertised Maximum Segment Size (MSS). So does this mean version 8.0 IOS doesn’t have this behavior..or the MPF is already coded in version 8.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Q2. If it is coded on version 8, then it must be placed with ACL for source any &amp;amp; destination any. So applying any – any is harmful &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="color: black;"&gt;Q3. In MPF we have entered the command &lt;/SPAN&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;set connection advanced-options mss-map. What does it mean?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="color: black;"&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;What is difference between &lt;/SPAN&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;sysopt connection tcpmss &lt;/STRONG&gt;&lt;SPAN style="mso-bidi-font-weight: bold;"&gt;&amp;amp; MPF&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="mso-bidi-font-weight: bold; color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="mso-bidi-font-weight: bold; color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Yogesh S&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 05:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/url-not-opening-via-pix/m-p/1466164#M856547</guid>
      <dc:creator>yogesh.suryawanshi</dc:creator>
      <dc:date>2010-08-17T05:24:42Z</dc:date>
    </item>
  </channel>
</rss>

