05-09-2016 08:46 PM - edited 03-12-2019 12:43 AM
Hello ,
We had a migration from an existing FWSM to ASA cluster.Configurations are exactly replicated with the new commands.
Issue description:-
We have two interfaces-Outside and DMZ.
Application server is in DMZ and a DB server is in outside.Application servers communicates to DB server on port 6516.
Telnet from Application server on port 6516 of DB servers is successfull,but the actual traffic is dropped.
Below is a capture in which resets can be found.
2: 14:09:34.189473 802.1Q vlan#34 P0 10.14.4.50.4121 > 10.20.90.190.6516: . ack 2648727807 win 63885 <nop,nop,sack sack 1 {2648729267:2648730145} >
3: 14:09:34.189534 802.1Q vlan#34 P0 10.14.4.50.4121 > 10.20.90.190.6516: . ack 2648727807 win 63885 <nop,nop,sack sack 1 {2648729267:2648730145} >
4: 14:09:34.189595 802.1Q vlan#34 P0 10.20.90.190.6516 > 10.14.4.50.4121: R 2648727807:2648727807(0) ack 3016827915 win 63885
Troubleshooting done:-
Removed sqlnet inspection from the global service policy - issue persist
Checked the mtu throught out the path.
Any help is a highly appreciated.
Regards
Gireesh
05-09-2016 09:00 PM
Hi Girish,
By
Can you change it to inspect port 6516 and then test ?
Use fixup protocol
If it still does not work please share the captures in .pcap format.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
05-26-2016 12:45 AM
hello,
I got resolved after changing the mss settings
Regards
Gireesh
04-10-2017 12:05 PM
Hi Girchand,
We are having similar issues after we migrate ASA HA to clustering, with SQLNET, what did you change with mtu settings, if you recall.
Thank You,
Mohan
04-10-2017 08:46 PM
Hello Mohan,
What is the sysopt connection tcpmss value configured?
Regards
Gireesh
04-11-2017 06:20 AM
Its 1380
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide