Hi my asa which is in production has been giving us issues for a while. It operate properly but then stops the flow of traffic. The interfaces stay up but the sites stops operation as I am no longer able to access service on that site. We are running OSPF between sites and have no VPN service running and no IPS services as well. The syslogs are also not helpful. We have replace the firewall twice with the same issue. can anyone shine a light. This morning it did the same and came back up by itself.
Is the ASA part of the OSPF routing or does it simply use static routes?
I would personally start the troubleshooting with the logs. I would attempt to generate traffic/connections to the server on the site facing these problems when its unreachable. Then I would locally monitor the logs through ASDM on the ASA and try to confirm if any traffic to the destination server from the client is seen on the ASA.
If the checking the logs is proving to be problematic you can always configure a traffic capture on the ASA directly. You can then do the same as above which is generating traffic/connections to the destination server while the server is unreachable. You can then record the time you were attempting those connections and later upload the captured data from the ASA to your computer and go through the captured data and compare the timestamps and see if the ASA has seen any of the traffic from the client attempting the connections.
You could also check the routing network or have someone else check it if that is not in your manage. If there is a problem with a certain connection (that might be likely in this situation) which then affects the adverticement of the subnets on (and behind) the ASA then someone should be able to see if there is probably freshly learned routes in the routing table related to the ASA.
I have not really faced a problem where the firewall itself would have stopped passing traffic OTHER THAN in situations where a configuration error has been made on it. But if this is not the case then I would doubt that the ASA is the actual source of the problem. We don't really have any information basis on your post what is actually happening on the ASA since you seem to think its causing the problems.
What is SecureX?
Cisco SecureX is included with all Secure Endpoint (formerly AMP for Endpoints) subscriptions. SecureX is a cloud-native platform that aggregates capabilities across your security environment. It’s designed to simplify your environment, ...
Cisco ISE Secure Wired Access Prescriptive Deployment Guide
Authors: Hariprasad Holla (until June 2018), Mahesh Nagireddy (until Dec 2018)
For an offline or printed copy of this document, simply choose ⋮ Options > Printer ...
Meet the Authors Slides- SecureX and the Evolution of Security Orchestration Automation and Response
(Live event – Wednesday, 20th, 2021 at 10:00 a.m. Pacific / 1:00 p.m. Eastern / 6:00 p.m. Paris)
This event had place on Wednesday 20th, January 202...
The following guide goes over the in and out of the Cisco Endpoints Security Analytics Dashboard as an overview and faq page
For more information on the product offering, licensing, support, and how to solution (TAC) guide links and more please visit the...
Join us live on Tuesday, January 19 at 10:00 am PT (and on demand after) as we discuss the latest version of ATT&CK and the expansion of TTPs in v8.
As a security expert, you are tasked with protecting your environment. You see the value of...