- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-16-2020 10:57 AM
Hi
Can anyone explain what(message-length maximum 512) and ("message-length maximum client auto") means and does please, and why ( message-length maximum) its set to 4096 on our ASA but 512 on our FTD's, and can the 512 setting on FTD cause any issues.?
also can anyone tell me how to use the connectivity over security on a per rule basis .??
much appreciated
Solved! Go to Solution.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2020 01:19 PM
Hi
Thanks for that, I did see where to use connectivity over security per rule, i was looking while a rule was set to trust it has to be allow so the drop down is available.
thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-16-2020 11:40 AM
I have seen this issue when i was using FWSM - when the MS Windows caused by Extension Mechanisms for DNS (EDNS0), this allows the use of UDP packets that are larger than 512 bytes. Some firewall systems do not like this and will drop the traffic.
ASA old code use message-length maximum 512
New ASA code support below command
message-length maximum client auto
This can be fixed with MS Windows side also.
use the connectivity over security on a per rule basis .??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-17-2020 01:19 PM
Hi
Thanks for that, I did see where to use connectivity over security per rule, i was looking while a rule was set to trust it has to be allow so the drop down is available.
thanks
