<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: delayed http lookups on 5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935172#M938629</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thats the name of the Default Inspection on your ASA. Its a name. Prove your name with "sh run".&lt;/P&gt;&lt;P&gt;In old PIX Version was the command "inspect...".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kind Regards&lt;/P&gt;&lt;P&gt;Ralf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 May 2008 07:51:14 GMT</pubDate>
    <dc:creator>stlieser</dc:creator>
    <dc:date>2008-05-06T07:51:14Z</dc:date>
    <item>
      <title>delayed http lookups on 5505</title>
      <link>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935167#M938624</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recently replaced a netgear firewall for an ASA5505. Below is my &lt;/P&gt;&lt;P&gt;config. My problem is that when I browse the web from my linux box, &lt;/P&gt;&lt;P&gt;anytime I hit a new site, it seems to take about 30 seconds to a minute &lt;/P&gt;&lt;P&gt;to do the lookup before I can actually get to the site. The DNS entries are &lt;/P&gt;&lt;P&gt;correct, so I don't really know why else it takes so long.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh run                  &lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.2(3) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname myhomenet&lt;/P&gt;&lt;P&gt;domain-name network.local&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.168.1.0 INSIDE&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address dhcp setroute &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;banner motd &lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 73.x.x.205&lt;/P&gt;&lt;P&gt; name-server 68.x.x.98&lt;/P&gt;&lt;P&gt; domain-name network.local&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-523.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http INSIDE 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet 192.168.1.11 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;telnet timeout 10&lt;/P&gt;&lt;P&gt;ssh INSIDE 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 10&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.20-192.168.1.40 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username winky password xxx&lt;/P&gt;&lt;P&gt;encrypted privilege 15&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:37:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935167#M938624</guid>
      <dc:creator>wizumwalt</dc:creator>
      <dc:date>2019-03-11T12:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: delayed http lookups on 5505</title>
      <link>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935168#M938625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What happens if you use an IP address rather than a URL in the web browser?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Apr 2008 13:53:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935168#M938625</guid>
      <dc:creator>rjrii</dc:creator>
      <dc:date>2008-04-28T13:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: delayed http lookups on 5505</title>
      <link>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935169#M938626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's hard for me to say. When I put in the domain name, it always takes a while, but it seems 1 out of 5 tries using the ip address will load pretty quickly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for the most part, it takes just as long whether it's w/ a domain name or ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Apr 2008 02:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935169#M938626</guid>
      <dc:creator>wizumwalt</dc:creator>
      <dc:date>2008-04-29T02:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: delayed http lookups on 5505</title>
      <link>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935170#M938627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try:&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;no dns domain-lookup inside&lt;/P&gt;&lt;P&gt;tcp-map MYTCPMAP&lt;/P&gt;&lt;P&gt;  exceed-mss allow&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt; match any&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 2048&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  no inspect http&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; class global-class&lt;/P&gt;&lt;P&gt;  set connection advanced-options MYTCPMAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Apr 2008 06:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935170#M938627</guid>
      <dc:creator>stlieser</dc:creator>
      <dc:date>2008-04-29T06:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: delayed http lookups on 5505</title>
      <link>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935171#M938628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I tried entering these commands and ran up against the following errors ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;winky(config)# dns domain-lookup outside &lt;/P&gt;&lt;P&gt;winky(config)# no dns domain-lookup inside&lt;/P&gt;&lt;P&gt;winky(config)# tcp-map MYTCPMAP&lt;/P&gt;&lt;P&gt;winky(config-tcp-map)# exceed-mss allow&lt;/P&gt;&lt;P&gt;winky(config-tcp-map)# class-map global-class&lt;/P&gt;&lt;P&gt;winky(config-cmap)# match any&lt;/P&gt;&lt;P&gt;winky(config-cmap)# policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;winky(config-pmap)# parameters&lt;/P&gt;&lt;P&gt;winky(config-pmap-p)# message-length maximum 2048&lt;/P&gt;&lt;P&gt;winky(config-pmap-p)# policy-map global_policy&lt;/P&gt;&lt;P&gt;winky(config-pmap)# class inspection_default&lt;/P&gt;&lt;P&gt;ERROR: % class-map inspection_default not configured&lt;/P&gt;&lt;P&gt;winky(config-pmap)# no inspect http&lt;/P&gt;&lt;P&gt;                           ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Apr 2008 01:21:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935171#M938628</guid>
      <dc:creator>wizumwalt</dc:creator>
      <dc:date>2008-04-30T01:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: delayed http lookups on 5505</title>
      <link>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935172#M938629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thats the name of the Default Inspection on your ASA. Its a name. Prove your name with "sh run".&lt;/P&gt;&lt;P&gt;In old PIX Version was the command "inspect...".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kind Regards&lt;/P&gt;&lt;P&gt;Ralf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2008 07:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delayed-http-lookups-on-5505/m-p/935172#M938629</guid>
      <dc:creator>stlieser</dc:creator>
      <dc:date>2008-05-06T07:51:14Z</dc:date>
    </item>
  </channel>
</rss>

