cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
232
Views
0
Helpful
1
Replies

How we can Scheule TCP connect in ciscoASA IOS 9.* Version

srikanth-setty
Level 1
Level 1

Hi ALL,

 

IP SLA,IP MONITOR these commands are not working in asa firewall,is there any alternate to schedule tcp traffic to bring tunnel up. or else can we send traffic from router through asa firewall to destination to bring tunnel up is this works.

 

Thanks

1 Reply 1

sdroy
Level 1
Level 1

For TCP scheduling on Cisco ASA with IOS 9.*, you can't utilize IP SLA or IP MONITOR because they are not supported on ASA appliances, but a decent workaround is to route the traffic to a router that is connected and supports these commands to generate periodic TCP packets. Another alternative is to activate TCP Keepalive on the ASA to keep it open, or utilize a customized script on a separate appliance to generate TCP packets on a periodic interval. Third-party monitoring tools like SolarWinds or PRTG can also be used to generate simulated traffic and keep the tunnel open.-zone traffic with a zone-pair configuration in the Zone-Based Firewall (ZBF). As a workaround, you can use internal DNS to resolve fish.example.com to 10.0.0.107 so that local clients do not require hairpin NAT, or you can use a NAT loopback configuration if your platform supports it. Also, verify and update your ZBF rules to permit intra-zone traffic explicitly.

Shuvodip Roy
Review Cisco Networking for a $25 gift card