08-03-2017 03:49 PM - edited 03-12-2019 02:46 AM
Hello
We have replaced our FWSM with the cisco ASA 5585-x (SSP-60).We have configured them in cluster mode. But some Oracle applications are losing connectivity to the database after replacement of Firewalls, Frequently.
The error on the application server is:
“Failed getting connection - at oradatabase.cpp(101) ORA-12547 : TNS: lost contact”
And error on the ASA is:
“Deny TCP (no connection) from appserver_ip/54864 to database_server_ip/1521 flags FIN ACK on interface Application_server_interface.”
The first thing we created IP ANY ANY rules on the interface that belongs to applications.
According to forum suggestions, we have disabled SQLNET global policy inspection.
The next thing, we have created a service policy (interface base) to match our application to database connection on TCP/1521 protocol.
Then we have setted up TCP connection properties on those streams to include the following details:
We also have configured TCP map in the TCP normalization options on that:
And in TCP option just “clear window scale” has enabled.
Does inspection on SQLNET ineffect by disabling SQLNET global policy inspection?
What‘s wrong with us?
Thank you.
08-03-2017 09:41 PM
Hi,
Please share the output of show run policy-map and show service-policy.
Regards,
Aditya
Please rate helpful and mark correct answers
08-04-2017 12:39 AM
08-04-2017 02:21 AM
Hi,
I see the service-policy is applied on two different interfaces:
policy-map
policy-map Interconnect-Billing-DB-policy
Can you let me know which is the one that is facing an issue?
Regards,
Aditya
Please rate helpful and mark correct answers
08-04-2017 02:54 AM
Hello
The policy-map Fruad-Web/App-Service-policy have confronted with problem.
Thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide