cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
591
Views
5
Helpful
1
Replies

Problem with TCP Connection

hi everyone,
I have ACL on the ASA that allow TCP connection between two networks. It works well, but sometimes ASA block this rule and I have to off und on this rule. Done it works again. I think it is because the TCP Stack between hosts in the networks is bad.
What can I do to ASA doesn't block the rule.

Best regards

1 Accepted Solution

Accepted Solutions

There are three options available:

  1. If it is really based on a bad TCP-stack of the endpoints, update them to a recent version or replace them.
  2. The ASA could have a bug that causes the traffic to be dropped. I recently had that with Citrix-traffic and an ASA update solved the problem.
  3. You could configure TCP-state-bypass to disable checks in the ASA.

View solution in original post

1 Reply 1

There are three options available:

  1. If it is really based on a bad TCP-stack of the endpoints, update them to a recent version or replace them.
  2. The ASA could have a bug that causes the traffic to be dropped. I recently had that with Citrix-traffic and an ASA update solved the problem.
  3. You could configure TCP-state-bypass to disable checks in the ASA.
Review Cisco Networking for a $25 gift card