cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1626
Views
0
Helpful
2
Replies

Why ASA Removes TCP Option Field.

Ravi_916
Level 1
Level 1

why ASA removes TCP option field, is there any security reason or something else.

Ex:- Think about BGP Authentication, MD5 hash carry into TCP Option 19 field, but by default ASA Removes TCP Option field. Why?

2 Replies 2

Muhammad Awais Khan
Cisco Employee
Cisco Employee

HI,

 

ASA inspection removes TCP option field due to a known bug "CSCua60046" which got fixed later on.

 

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCua60046

 

affected release: 8.4(4), 8.4(3.8)

but it's also happens on ASA 9.6

Review Cisco Networking for a $25 gift card