01-27-2011 07:47 PM - edited 03-11-2019 12:41 PM
Hi everybody
I have a rather tricky challenge:
(problem identified but not solved yet)
We have a MS-OWA frontend (yes, not the new ISA) on the DMZ communicating with the Exchange backend and a DC cluster (3 DCs altogether with different functions scattered among them like global catalog etc...) on the inside. At the moment I need to permit quite generously traffic from OWA frontend to Exchange backend and DCs. That's because some rpc connections don't use the epm, it shows clearly on the debug rpc and the behaviour matches pretty closely the "caveats" of rpc inspection.
ASA 8.3 main line does not support dce-rpc without end point mapper. I heard about an interim release 8.3.2(4) which should fix it.
Has anyone experinece with that version in the field? Is it worth the upgrade? (we have a smartnet contract for the ASA)
Input and thoughts are highly appreciated.
Rgds,
MiKa
PS I've read the release notes on http://www.cisco.com/web/software/280775065/38969/ASA-832-Interim-Release-Notes.html
Solved! Go to Solution.
01-29-2011 05:39 AM
Are you talkinga bout this ENH caveat?
Symptom:
This is an enhancement request to allow DCERPC inspection to open pinholes for non-epm exchanges.
Further Problem Description:
RemoteCreateInstance requests and response initiate new connections in the RPC protocol. Currently the ASA only identifes and inspect EPM exchanges with the DCERPC protocol.
This has been resolved in the codes:8.3.2(1)
If you are running 8.3.2(4) it should have the fix.
-KS
Can not view this .txt file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=DDTS_History&ext=txt&type=FILE
Can not view this .txt file attachment inline, please click on the following link to view the attachment.
http:///cdts/siebel/siebsrvr/input/CSCsj28231/62/CSCsk97762_DDTS_History.txt
Can not view this .cap file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=Prod_st&ext=cap&type=FILE
Can not view this .cap file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-acmilan-idfw-by-cl117252&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-acmilan-main-by-cl117145&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-acmilan-phase2-by-cl117177&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-acmilan-sia-vmdq2-by-cl117188&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-8.3.2_fcs_throttle-by-cl116938&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-bennu-by-cl116991&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-bennu-osiris-by-cl117100&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-dcerpc-by-cl111207&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-dcerpc-by-cl97941&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-dcerpc2-by-cl111238&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-dcerpc2-by-cl111239&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-main-by-cl116934&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this .cap file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=outside&ext=cap&type=FILE
Can not view this .cap file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=static-analysis-broadview-dcerpc&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=static-analysis-broadview-dcerpc.p2&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
01-30-2011 10:24 AM
Hello Mika, it is tested in Cisco labs and hence documented. So I suggest moving to that version for the fix.
Sent from Cisco Technical Support iPhone App
-- Please rate the solutions
01-27-2011 10:31 PM
Hello Mika,
From the internal documentation on the bug and the attached cases I don't see anyone specifically having tried this version. But I could see that they used workarounds such as opening ports > 1024 for specific hosts in concern. But according to the release notes this should be fixed. So I would suggest giving it a try.
Sent from Cisco Technical Support iPhone App
01-28-2011 07:32 AM
Thx Lourdes,
that's what i'm doing now opening tcp >1024 which is not really a good solution.
Would you recommend to try the interim? Was it tried out in the Cisco Labs?
Rgds,
MiKa
01-29-2011 05:39 AM
Are you talkinga bout this ENH caveat?
Symptom:
This is an enhancement request to allow DCERPC inspection to open pinholes for non-epm exchanges.
Further Problem Description:
RemoteCreateInstance requests and response initiate new connections in the RPC protocol. Currently the ASA only identifes and inspect EPM exchanges with the DCERPC protocol.
This has been resolved in the codes:8.3.2(1)
If you are running 8.3.2(4) it should have the fix.
-KS
Can not view this .txt file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=DDTS_History&ext=txt&type=FILE
Can not view this .txt file attachment inline, please click on the following link to view the attachment.
http:///cdts/siebel/siebsrvr/input/CSCsj28231/62/CSCsk97762_DDTS_History.txt
Can not view this .cap file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=Prod_st&ext=cap&type=FILE
Can not view this .cap file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-acmilan-idfw-by-cl117252&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-acmilan-main-by-cl117145&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-acmilan-phase2-by-cl117177&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-acmilan-sia-vmdq2-by-cl117188&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-8.3.2_fcs_throttle-by-cl116938&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-bennu-by-cl116991&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-bennu-osiris-by-cl117100&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-dcerpc-by-cl111207&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-dcerpc-by-cl97941&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-dcerpc2-by-cl111238&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-dcerpc2-by-cl111239&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=fixed-in-broadview-main-by-cl116934&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this .cap file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=outside&ext=cap&type=FILE
Can not view this .cap file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=static-analysis-broadview-dcerpc&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://cdetsweb-prd.cisco.com/apps/dumpcr_att?identifier=CSCsk97762&title=static-analysis-broadview-dcerpc.p2&ext=&type=FILE
Can not view this . file attachment inline, please click on the following link to view the attachment.
http://
01-30-2011 10:24 AM
Hello Mika, it is tested in Cisco labs and hence documented. So I suggest moving to that version for the fix.
Sent from Cisco Technical Support iPhone App
-- Please rate the solutions
01-31-2011 03:35 AM
Dear Poonguzhali Sankar, dear Lourdes Gino D,
Thanks for your help - I will upgrade to the interim on the next possible service window...
best regards,
MiKa
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide