Thanks Michael, What does http fixup do ? how would disabling fixup fix my issue ?
Aaron -----Original Message----- From: Michael Malitsky [mailto:[email protected]] Sent: Thursday, July 11, 2013 2:49 PM To: [email protected]; [email protected] Subject: Re: [c-nsp] pix 6.1(3) Sounds eerily familiar, although I can't find any notes for v6. The first releases of 7 had a similar issue, caused by the firewall dropping any packets with MSS>negotiated size. However, you options are very few. Try disabling the http fixup to confirm it is the inspection engine causing the problem. In version 6, there is no way to tune the inspection engines, on/off is the only button, so your only option is to upgrade. I suggest trying 6.5.last (I think 6.5.105), if that doesn't work go to 7, the highest version that supports a PIX. In v7 you can at least exempt the problem traffic from inspection. Best option - upgrade to an ASA. Michael ------------------------------ Date: Thu, 11 Jul 2013 09:51:16 -0500 From: "Aaron" <[email protected]> To: <[email protected]> Subject: [c-nsp] pix 6.1(3) Message-ID: <[email protected]> Content-Type: text/plain; charset="us-ascii" Anyone ever dealt with a weird issue whereas when going to a certain website via a cisco pix, the tcp syn and syn/ack flow fine, but the final ack is lost inside the pix. ? my sniffs seems to show this. Aaron = _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
