02-24-2015 08:05 AM - edited 03-11-2019 10:33 PM
Hi, there.
We have an pair of ASA5585-40 HA running 9.1(3), due to this bug CSCui77398, we noticed from the ASA syslog messages that there are valid connection being closed by ICMP Inspection, we do have ICMP inspection enabled since there are quite a few applications depends on successful PING to work properly.
Just wondering has any one run into this bug? and which version has this successfully addressed? I do have TAC case opened, but TAC is unable to confirm which release has this bug addressed.
The ASA syslog will display something like :".......Flow closed by inspection", also "show service-policy | in icmp" in my case has the following output.
Inspect: icmp, packet 1302002238, lock fail 0, drop 2119758, reset-drop 0, v6-fail-close 0
Leo Song
02-28-2015 01:01 PM
Hi,
This defect should be fixed on your current OS 9.1.3.
If you are still getting the traffic drop , try to verify the drops with the syslog.
Thanks and Regards,
Vibhor Amrodia
03-02-2015 06:31 AM
According to Cisco bug report here, this bug should have been addressed in 9.1(3), however, we are running 9.1(3) and can confirm this bug is not addressed by 1) "show service-policy | in icmp" and 2) ASA syslogs.
I opened a TAC case and engineer suggests me to upgrade to 9.1(4) simply this bug "should be fixed". I went through the release of 9.2 and 9.3, neither of them mention this bug either still being or has been fixed. That's why I am asking community to help.
Leo
03-02-2015 07:02 AM
Hi,
I can verify that this defect is fixed on the ASA 9.1.3 code.
Are you seeing the Syslogs and intermittent TCP connection drops on the ASA device ?
Also , do they go away if you disable the ICMP inspection ?
Thanks and Regards,
Vibhor Amrodia
03-02-2015 07:57 AM
Here are the facts:
All of the above facts make me believe this bug has not been addresses in 9.1(3).
If, it has been fully addressed like you and my TAC case engineer suggested, could it be the case that I hit something else?
Also, would you recommend upgrade to 9.2 or 9.3?
Leo
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: