<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CBAC is blocking some website content in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118367#M915257</link>
    <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to be having issues with CBAC on a 877.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried accessing certain webpages without the CBAC setting and there is no issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some websites seem fine, whereas others partially load or not at all.  For example elements of the cisco homepage do not load, specifically the animated section.  I have test a few websites and some don't seem to come up all all, youtube and ebay are a couple of example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My CBAC configuration should be pretty standard, I have an ACL denying almost everything except some ICMP (it starts deny UPD/TCP then allows ICMP), and the inspect statements cover most protocols.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have noticed that my deny ACL statement is blocking some packets...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:25:41 GMT</pubDate>
    <dc:creator>davidjbradley</dc:creator>
    <dc:date>2019-03-11T13:25:41Z</dc:date>
    <item>
      <title>CBAC is blocking some website content</title>
      <link>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118367#M915257</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to be having issues with CBAC on a 877.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried accessing certain webpages without the CBAC setting and there is no issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some websites seem fine, whereas others partially load or not at all.  For example elements of the cisco homepage do not load, specifically the animated section.  I have test a few websites and some don't seem to come up all all, youtube and ebay are a couple of example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My CBAC configuration should be pretty standard, I have an ACL denying almost everything except some ICMP (it starts deny UPD/TCP then allows ICMP), and the inspect statements cover most protocols.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have noticed that my deny ACL statement is blocking some packets...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118367#M915257</guid>
      <dc:creator>davidjbradley</dc:creator>
      <dc:date>2019-03-11T13:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: CBAC is blocking some website content</title>
      <link>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118368#M915261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try adjusting your CBAC config to *only* inspect TCP, UDP, and FTP and see if that makes a difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2008 22:04:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118368#M915261</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-05T22:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: CBAC is blocking some website content</title>
      <link>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118369#M915265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;through what you said &lt;/P&gt;&lt;P&gt;i guess is related to flash player and JAVA&lt;/P&gt;&lt;P&gt;just track those things&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 02:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118369#M915265</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-08-06T02:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: CBAC is blocking some website content</title>
      <link>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118370#M915269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi I solved my issue.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"ip virtual-reassembly" was disabled and it appears that the fragments were getting dropped by the firewall policies.  I still don't really understand why this causes issues with some issues, but I must be realed to the content in the HTML.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 06:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-is-blocking-some-website-content/m-p/1118370#M915269</guid>
      <dc:creator>davidjbradley</dc:creator>
      <dc:date>2008-08-06T06:23:04Z</dc:date>
    </item>
  </channel>
</rss>

