<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5520 - Sqlnet inspection dropping connections in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-sqlnet-inspection-dropping-connections/m-p/1268207#M858527</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After one year and 3 months without any problems I had to upgrade the ASA 5520 from version 8.03 to 8.04 due to a known bug (tcpmss problem).&lt;/P&gt;&lt;P&gt;Everything worked fine with one exception: the Oracle application is not working any more.&lt;/P&gt;&lt;P&gt;Whenever I remove the sqlnet inspection the application works fine.&lt;/P&gt;&lt;P&gt;It can perform some simple queries, however, I realized that after a query containg a clob field in Oracle the connection are dropped by the ASA.&lt;/P&gt;&lt;P&gt;Below you can find the debug msgs and &lt;/P&gt;&lt;P&gt;logging messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# debug sqlnet 255&lt;/P&gt;&lt;P&gt;PROBLEM HERE -&amp;gt; SQLNet: received partial fragment, frag len: 1732, partial frag len: 1380, 352 bytes needed&lt;/P&gt;&lt;P&gt;SQLNet: received whole fragment, 1732 bytes&lt;/P&gt;&lt;P&gt;SQLNet: using proxy forward&lt;/P&gt;&lt;P&gt;SQLNet: received a new complete fragment of 289 bytes&lt;/P&gt;&lt;P&gt;SQLNet: received a new complete fragment of 21 bytes&lt;/P&gt;&lt;P&gt;SQLNet: received a new complete fragment of 155 bytes&lt;/P&gt;&lt;P&gt;PROBLEM HERE -&amp;gt; SQLNet: received partial fragment, frag len: 2011, partial frag len: 1380, 631 bytes needed&lt;/P&gt;&lt;P&gt;SQLNet: received whole fragment, 2011 bytes&lt;/P&gt;&lt;P&gt;SQLNet: using proxy forward&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# syslog msgs:&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44946 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44951 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44955 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44958 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44959 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44960 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:59 asa Jul 18 2009 23:58:04: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44965 flags ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-302014: Teardown TCP connection 138604883 for DMZ:dbserver-dmz/1521 to Internal:adm-int/44985 duration 0:00:36 bytes 2001924 Flow closed by inspection&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44985 flags ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44985 flags PSH ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44985 flags ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44985 flags PSH ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from adm-int/44985 to dbserver-dmz/1521 flags ACK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The dbserver is on the DMZ interface and the system is on the Internal interface. Traffic is allowed and it was working with the inspection on version 8.03.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcelo Pinheiro&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:57:15 GMT</pubDate>
    <dc:creator>m.pinheiro</dc:creator>
    <dc:date>2019-03-11T15:57:15Z</dc:date>
    <item>
      <title>ASA 5520 - Sqlnet inspection dropping connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sqlnet-inspection-dropping-connections/m-p/1268207#M858527</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After one year and 3 months without any problems I had to upgrade the ASA 5520 from version 8.03 to 8.04 due to a known bug (tcpmss problem).&lt;/P&gt;&lt;P&gt;Everything worked fine with one exception: the Oracle application is not working any more.&lt;/P&gt;&lt;P&gt;Whenever I remove the sqlnet inspection the application works fine.&lt;/P&gt;&lt;P&gt;It can perform some simple queries, however, I realized that after a query containg a clob field in Oracle the connection are dropped by the ASA.&lt;/P&gt;&lt;P&gt;Below you can find the debug msgs and &lt;/P&gt;&lt;P&gt;logging messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# debug sqlnet 255&lt;/P&gt;&lt;P&gt;PROBLEM HERE -&amp;gt; SQLNet: received partial fragment, frag len: 1732, partial frag len: 1380, 352 bytes needed&lt;/P&gt;&lt;P&gt;SQLNet: received whole fragment, 1732 bytes&lt;/P&gt;&lt;P&gt;SQLNet: using proxy forward&lt;/P&gt;&lt;P&gt;SQLNet: received a new complete fragment of 289 bytes&lt;/P&gt;&lt;P&gt;SQLNet: received a new complete fragment of 21 bytes&lt;/P&gt;&lt;P&gt;SQLNet: received a new complete fragment of 155 bytes&lt;/P&gt;&lt;P&gt;PROBLEM HERE -&amp;gt; SQLNet: received partial fragment, frag len: 2011, partial frag len: 1380, 631 bytes needed&lt;/P&gt;&lt;P&gt;SQLNet: received whole fragment, 2011 bytes&lt;/P&gt;&lt;P&gt;SQLNet: using proxy forward&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# syslog msgs:&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44946 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44951 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44955 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44958 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44959 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:58 asa Jul 18 2009 23:58:02: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44960 flags FIN ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:56:59 asa Jul 18 2009 23:58:04: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44965 flags ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-302014: Teardown TCP connection 138604883 for DMZ:dbserver-dmz/1521 to Internal:adm-int/44985 duration 0:00:36 bytes 2001924 Flow closed by inspection&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44985 flags ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44985 flags PSH ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44985 flags ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from dbserver-dmz/1521 to adm-int/44985 flags PSH ACK  on interface DMZ&lt;/P&gt;&lt;P&gt;Jul 18 23:57:13 asa Jul 18 2009 23:58:17: %ASA-6-106015: Deny TCP (no connection) from adm-int/44985 to dbserver-dmz/1521 flags ACK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The dbserver is on the DMZ interface and the system is on the Internal interface. Traffic is allowed and it was working with the inspection on version 8.03.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcelo Pinheiro&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sqlnet-inspection-dropping-connections/m-p/1268207#M858527</guid>
      <dc:creator>m.pinheiro</dc:creator>
      <dc:date>2019-03-11T15:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - Sqlnet inspection dropping connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sqlnet-inspection-dropping-connections/m-p/1268208#M858529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran into a similar issue at a client and what is happening is there isn't a two way connection between the client and the server.  There were two things we did that clear this up.  One was to turn of sqlnet inspection and the other was to have the client that was having the issue restart their computer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jul 2009 00:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sqlnet-inspection-dropping-connections/m-p/1268208#M858529</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2009-07-21T00:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - Sqlnet inspection dropping connections</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sqlnet-inspection-dropping-connections/m-p/1268209#M858531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your response. The first option I already did and it is working.&lt;/P&gt;&lt;P&gt;The second is impossible because it is an application server.&lt;/P&gt;&lt;P&gt;I was wondering if there is a way to keep sqlnet inspecting with this problem or is it a bug?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jul 2009 22:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sqlnet-inspection-dropping-connections/m-p/1268209#M858531</guid>
      <dc:creator>m.pinheiro</dc:creator>
      <dc:date>2009-07-21T22:10:44Z</dc:date>
    </item>
  </channel>
</rss>

