<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP Acked lost segment - VideoConference Setup through ASA-5 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031743#M916172</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try the 'invalid-ack' option, it drops by default:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/protect.html#wp1066238" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/protect.html#wp1066238&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either enable it for this specific flow or for all traffic (to test).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Jul 2008 01:17:04 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-07-31T01:17:04Z</dc:date>
    <item>
      <title>TCP Acked lost segment - VideoConference Setup through ASA-5520</title>
      <link>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031740#M916162</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am having the following issue with a videoconference call.  I have an ASA-5520 in transparent firewall mode in the middle of a LAN connections between two campus.&lt;/P&gt;&lt;P&gt;When I remove the firewall the videoconference works fine.&lt;/P&gt;&lt;P&gt;When the firewall is connected the call can not be completed.  &lt;/P&gt;&lt;P&gt;The call originating station first contacts a gatekeeper in order to establish the call.  I captured the traffic between this station and the gatekeeper using a sniffer and I found that the problem is that apparently there are segments lost in the communication.  This problem appears in every SYN,ACK packet received from the gatekeeper, therefore the station responds with a RST of the connection.  &lt;/P&gt;&lt;P&gt;ASA is running software 8.0(2). &lt;/P&gt;&lt;P&gt;Does anybody know if there is some way to fix this issue from configuration?&lt;/P&gt;&lt;P&gt;I am completely sure there is no problem with access-lists and I am not inspecting H323, H225, ras, etc...&lt;/P&gt;&lt;P&gt;Attached is a copy of the sniffer capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031740#M916162</guid>
      <dc:creator>javiercastro</dc:creator>
      <dc:date>2019-03-11T13:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Acked lost segment - VideoConference Setup through ASA-5</title>
      <link>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031741#M916164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have you tried to enable inspection H323, H225, ras?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 15:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031741#M916164</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2008-07-23T15:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Acked lost segment - VideoConference Setup through ASA-5</title>
      <link>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031742#M916170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I tried enabling inspection, disabling tcp sequence randomization.&lt;/P&gt;&lt;P&gt;Still not working.  Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2008 22:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031742#M916170</guid>
      <dc:creator>javiercastro</dc:creator>
      <dc:date>2008-07-30T22:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Acked lost segment - VideoConference Setup through ASA-5</title>
      <link>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031743#M916172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try the 'invalid-ack' option, it drops by default:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/protect.html#wp1066238" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/protect.html#wp1066238&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either enable it for this specific flow or for all traffic (to test).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2008 01:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031743#M916172</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-31T01:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Acked lost segment - VideoConference Setup through ASA-5</title>
      <link>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031744#M916175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;after several traffic captures gathered, I have figured out that something in the inside network is messing with the ack number.  Very weird problem since I have only the Vlan interface in the 4506, everything else is L2 Switched network to the videoconference station.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2008 14:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031744#M916175</guid>
      <dc:creator>javiercastro</dc:creator>
      <dc:date>2008-08-13T14:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Acked lost segment - VideoConference Setup through ASA-5</title>
      <link>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031745#M916179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So have you managed to resolve this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2008 17:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-acked-lost-segment-videoconference-setup-through-asa-5520/m-p/1031745#M916179</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-13T17:43:25Z</dc:date>
    </item>
  </channel>
</rss>

