<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What does IP Options: &amp;quot;Router Alert&amp;quot; specify? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107434#M894053</link>
    <description>&lt;P&gt;We have a client using a Tanberg video device to connect to  a Polycom through our ASA.&lt;/P&gt;&lt;P&gt;We are seeing error messages as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(IPs have been changed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-6-106012: Deny IP from 192.168.18.20 to 172.22.54.29, IP options: "Router Alert" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody have any experience with this particular error?&lt;/P&gt;&lt;P&gt;Is it a false alarm? Should I (or can I)&lt;/P&gt;&lt;P&gt;allow this traffic from a trusted host inside our network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any info-&lt;/P&gt;&lt;P&gt;Lynne&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 14:07:58 GMT</pubDate>
    <dc:creator>lynne.meeks</dc:creator>
    <dc:date>2019-03-11T14:07:58Z</dc:date>
    <item>
      <title>What does IP Options: "Router Alert" specify?</title>
      <link>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107434#M894053</link>
      <description>&lt;P&gt;We have a client using a Tanberg video device to connect to  a Polycom through our ASA.&lt;/P&gt;&lt;P&gt;We are seeing error messages as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(IPs have been changed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-6-106012: Deny IP from 192.168.18.20 to 172.22.54.29, IP options: "Router Alert" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody have any experience with this particular error?&lt;/P&gt;&lt;P&gt;Is it a false alarm? Should I (or can I)&lt;/P&gt;&lt;P&gt;allow this traffic from a trusted host inside our network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any info-&lt;/P&gt;&lt;P&gt;Lynne&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107434#M894053</guid>
      <dc:creator>lynne.meeks</dc:creator>
      <dc:date>2019-03-11T14:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: What does IP Options: "Router Alert" specify?</title>
      <link>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107435#M894054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lynne,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106012&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error Message    %PIX|ASA-6-106012: Deny IP from IP_address to IP_address, IP options hex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Explanation    This is a packet integrity check message. An IP packet was seen with IP options. Because IP options are considered a security risk, the packet was discarded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Action    Contact the remote host system administrator to determine the problem. Check the local site for loose source routing or strict source routing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa70/system/message/logmsgs.html#wp1279793" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/system/message/logmsgs.html#wp1279793&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2008 20:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107435#M894054</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-11-04T20:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: What does IP Options: "Router Alert" specify?</title>
      <link>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107436#M894055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to disable the packet integrity check on&lt;/P&gt;&lt;P&gt;an ASA 5510 - or at least prevent the check from specific sources&lt;/P&gt;&lt;P&gt; - and if so, how?&lt;/P&gt;&lt;P&gt;I am getting these errors from our campus to campus video conferencing using Polycoms and I simply want this security check out of the picture for these connections.&lt;/P&gt;&lt;P&gt;Thanks, Forrest&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 17:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107436#M894055</guid>
      <dc:creator>frbaker07</dc:creator>
      <dc:date>2011-01-13T17:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: What does IP Options: "Router Alert" specify?</title>
      <link>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107437#M894056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Forrest,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We started seeing this problem more and more, so we changed the ASA code accordingly. Starting in version 8.2(2) the ASA gained the ability to have the configuration specify how it should treat ip options like router alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the release notes for 8.2(2) here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/release/notes/asarn82.html#wp424893"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/release/notes/asarn82.html#wp424893&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the configuration guide section on ip options shows how to configure the ASA:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/inspect_basic.html#wp1548725"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/inspect_basic.html#wp1548725&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An upgrade to version 8.2(4) would do the trick. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you plan upgrade to version 8.3, please read and understand this document first:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12690"&gt;https://supportforums.cisco.com/docs/DOC-12690&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the upgrade, the policy-map configuration would look like below (the new config is the 'inspect ip-options' command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ASA# sh run policy-map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;policy-map global_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; class inspection_default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; inspect ip-options &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 23:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-ip-options-quot-router-alert-quot-specify/m-p/1107437#M894056</guid>
      <dc:creator>Jay Johnston</dc:creator>
      <dc:date>2011-01-13T23:25:12Z</dc:date>
    </item>
  </channel>
</rss>

