cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
973
Views
5
Helpful
1
Replies

Problem with TCP Connection

hi everyone,
I have ACL on the ASA that allow TCP connection between two networks. It works well, but sometimes ASA block this rule and I have to off und on this rule. Done it works again. I think it is because the TCP Stack between hosts in the networks is bad.
What can I do to ASA doesn't block the rule.

Best regards

1 Accepted Solution

Accepted Solutions

There are three options available:

  1. If it is really based on a bad TCP-stack of the endpoints, update them to a recent version or replace them.
  2. The ASA could have a bug that causes the traffic to be dropped. I recently had that with Citrix-traffic and an ASA update solved the problem.
  3. You could configure TCP-state-bypass to disable checks in the ASA.
--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

View solution in original post

1 Reply 1

There are three options available:

  1. If it is really based on a bad TCP-stack of the endpoints, update them to a recent version or replace them.
  2. The ASA could have a bug that causes the traffic to be dropped. I recently had that with Citrix-traffic and an ASA update solved the problem.
  3. You could configure TCP-state-bypass to disable checks in the ASA.
--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Review Cisco Networking for a $25 gift card