03-28-2006 02:41 PM - edited 02-21-2020 12:48 AM
Recently upgrade a PIX 515e from 6.34 to 7.12. Everything seemed to worked ok, but having a problem accessing some web sites. Basically, we allow all IP traffic from the 'inside' network. Some errors from log are:
609001: Built local-host outide:199.230.128.100
106015: Deny TCP (no connection) from djm/1646 to 199.230.128.100/80 flags ACK on interface inside
609002: teardown local-host ouside: 199.230.128.100 duration 0:00:00
Config is attached.....
Solved! Go to Solution.
03-29-2006 03:04 PM
We are also seeing problems on the same platform. Have removed the HTTP inspection from the default inspection rule as a temporary workaround:
policy-map global_policy
class inspection_default
no inspect http
Still looking for a solution...
03-28-2006 09:44 PM
03-29-2006 03:04 PM
We are also seeing problems on the same platform. Have removed the HTTP inspection from the default inspection rule as a temporary workaround:
policy-map global_policy
class inspection_default
no inspect http
Still looking for a solution...
04-06-2006 12:59 AM
We hit the same bug yesterday - downgraded the Pix to 7.1.1 and it works fine. Bit of an annoying bug!
04-10-2006 09:56 AM
Hi all,
It turns out that when you upgrade from 6.3 to 7.1, you cannot do it in one go, rather you would have to upgrade to version 7.0 first, then upgrade from 7.0 to 7.1, we tried this and we did not hear any complains from our customer...
Hope that helps, please don't forget to rate...
Regards,
04-06-2006 05:17 AM
Looks like a known issue with mss
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml
04-10-2006 09:28 AM
I am also having this issue. lr.moore, you have helped me on EE as well, and you are a lot better than me at this stuff. Although, I don't think this is an MSS issue. I already have the MSS configured so I added a site to the access list that is now having the issue. It did not resolve the problem. Once I disabled http inspection, all was good. There are also more posts on the same issue on these forums, in case anyone wants to read more on it.
I think this is more a function of the fixup/inspection.
I also noticed some weird stuff with the ESMTP (which is enabled by default I think in 7.1.2). I disabled the ESMTP and everything was great again as well.
04-10-2006 09:59 AM
Hi all,
It turns out that when you upgrade from 6.3 to 7.1, you cannot do it in one go, rather you would have to upgrade to version 7.0 first, then upgrade from 7.0 to 7.1, we tried this and we did not hear any complains from our customer...
Hope that helps, please don't forget to rate...
Regards,
04-10-2006 11:11 AM
I actually have an ASA5510 that started at 7.04 and I upgraded to 7.1.2. Do you have the http inspection enabled? I've got to believe this is a wide spread bug as I am not doing anything even close to complicated with the device.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide