<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;[Config] Cisco 2821 Router - Firewall Mysteriously Dropped Packe&#x27; in forum &#x27;Cisco&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Config-Cisco-2821-Router-Firewall-Mysteriously-Dropped-Packe-23107745</link>
<description></description>
<language>en</language>
<pubDate>Thu, 20 Jun 2013 06:52:17 EDT</pubDate>
<lastBuildDate>Thu, 20 Jun 2013 06:52:17 EDT</lastBuildDate>

<item>
<title>Re: [Config] Cisco 2821 Router - Firewall Mysteriously Dropped P</title>
<link>http://www.dslreports.com/forum/Re-Config-Cisco-2821-Router-Firewall-Mysteriously-Dropped-P-23116792</link>
<description><![CDATA[a9a1c1 posted : You have Virtual Reassembly tuned off on your multilink interface and Virtual Reassembly tuned on in your Gigabit Interface,  I think that's causing issues with the firewall and or the Multilink T1s.  Try turning off this:<br><br>Interface Gig0/0<br>no ip virtual-reassembly<br><br>and see what you get. When the packets cross this interface it allows them to get a sequence number, since there broken up to 1500 bite packets, and be routed. Since you have this turned off on your multilink the sequence number gets dropped on the return trip. Andrew]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Config-Cisco-2821-Router-Firewall-Mysteriously-Dropped-P-23116792</guid>
<pubDate>Thu, 01 Oct 2009 20:55:03 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Cisco 2821 Router - Firewall Mysteriously Dropped P</title>
<link>http://www.dslreports.com/forum/Re-Config-Cisco-2821-Router-Firewall-Mysteriously-Dropped-P-23112874</link>
<description><![CDATA[cooldude9919 posted : Almost seems like a MTU or fragmenting issue.  I havent seen that error message before and we do zbfw also.  Its griping about an invalud seq# and is dropping because of that, not because of some other reason.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Config-Cisco-2821-Router-Firewall-Mysteriously-Dropped-P-23112874</guid>
<pubDate>Thu, 01 Oct 2009 11:03:50 EDT</pubDate>
</item>

<item>
<title>[Config] Cisco 2821 Router - Firewall Mysteriously Dropped Packe</title>
<link>http://www.dslreports.com/forum/Config-Cisco-2821-Router-Firewall-Mysteriously-Dropped-Packe-23107745</link>
<description><![CDATA[anon posted : Hello Everyone,<br><br>I'm new to this Board and am at my wit's end. I do not have any Cisco certifications but have used a variety of their devices, this is my first endeavor into the IOS world however.<br><br>I have done a fair bit of searching and could find no relevant posts to issue.<br><br>I have a Cisco 2821 (revision 53.50), running Cisco IOS Software, 2800 Software (C2800NM-ADVSECURITYK9-M), Version 12.4(24)T1, RELEASE SOFTWARE (fc3).<br><br>I am using the Zone Based Firewall and have so far been able to configure it successfully. My problem arises when I try to allow the following traffic to a specific computer (10.10.20.5) on my internal network:<br><br>5060 UDP, TCP<br>10,000-10,500 UDP<br>5222 TCP<br>843 TCP<br><br>It should be noted that port 5060 is SIP however my particular implementation requires that SIP inspection be disabled. The SIP packets are the ones I am having trouble with...<br><br>When I configure "ip inspect log drop-pkt" and enable terminal monitoring I am shown dropped packets:<br><br>000074: Sep 30 08:24:59.632 MDT: %FW-6-DROP_PKT: Dropping udp session 64.201.102.162:53402 10.10.20.5:5060 due to Invalid Seq# with ip ident 0<br>000075: Sep 30 08:25:30.793 MDT: %FW-6-DROP_PKT: Dropping udp session 63.253.254.250:9870 10.10.20.5:5060 due to Invalid Seq# with ip ident 0<br>000076: Sep 30 08:26:01.134 MDT: %FW-6-DROP_PKT: Dropping udp session 64.201.102.162:53402 10.10.20.5:5060 due to Invalid Seq# with ip ident 0<br>000077: Sep 30 08:26:31.154 MDT: %FW-6-DROP_PKT: Dropping udp session 98.243.175.140:61070 10.10.20.5:5060 due to Invalid Seq# with ip ident 0<br><br>Here is my config (with some sensitive lines edited):<br><br>version 12.4<br>no service pad<br>service tcp-keepalives-in<br>service tcp-keepalives-out<br>service timestamps debug datetime msec localtime show-timezone<br>service timestamps log datetime msec localtime show-timezone<br>service password-encryption<br>service sequence-numbers<br>!<br>hostname bdbfrouter<br>!<br>boot-start-marker<br>boot system flash:c2800nm-advsecurityk9-mz.124-24.t1.bin<br>boot-end-marker<br>!<br>card type t1 0 0<br>security authentication failure rate 3 log<br>security passwords min-length 6<br>logging message-counter syslog<br>logging buffered 4096<br>enable secret 5 blahblahblah<br>!<br>aaa new-model<br>!<br>!<br>aaa authentication login local_authen local<br>aaa authorization exec local_author local<br>!<br>!<br>aaa session-id common<br>clock timezone MDT -7<br>clock summer-time MDT date Apr 6 2003 2:00 Oct 26 2003 2:00<br>no network-clock-participate wic 0<br>!<br>dot11 syslog<br>no ip source-route<br>!<br>!<br>ip cef<br>ip dhcp excluded-address 192.168.11.1 192.168.11.11<br>!<br>ip dhcp pool GuestWiFi<br>import all<br>network 192.168.11.0 255.255.255.0<br>dns-server 66.255.85.8 66.255.85.9<br>default-router 192.168.11.1<br>!<br>!<br>ip port-map user-Switchboard1 port tcp 5222<br>ip port-map user-Switchboard2 port tcp 843<br>ip port-map user-Switchvox port udp from 10000 to 10500 description ports for VoIP phones<br>no ip bootp server<br>ip domain name domain.local<br>ip name-server 66.255.85.8<br>ip name-server 66.255.85.9<br>ntp update-calendar<br>ntp server 10.10.20.200 source GigabitEthernet0/0<br>!<br>multilink bundle-name authenticated<br>!<br>parameter-map type protocol-info msn-servers<br>server name messenger.hotmail.com<br>server name gateway.messenger.hotmail.com<br>server name webmessenger.msn.com<br><br>parameter-map type protocol-info aol-servers<br>server name login.oscar.aol.com<br>server name toc.oscar.aol.com<br>server name oam-d09a.blue.aol.com<br><br>parameter-map type protocol-info yahoo-servers<br>server name scs.msg.yahoo.com<br><br>!<br>!<br>crypto pki trustpoint test_trustpoint_config_created_for_sdm<br>subject-name e=sdmtest@sdmtest.com<br>revocation-check crl<br>!<br>crypto pki trustpoint SSLCERT<br>enrollment selfsigned<br>serial-number<br>ip-address 73.243.75.98<br>revocation-check crl<br>!<br>!<br>crypto pki certificate chain test_trustpoint_config_created_for_sdm<br>crypto pki certificate chain SSLCERT<br>certificate self-signed 0B<br>::certdata::<br>quit<br>!<br>!<br>username admin privilege 15 secret 5 blahblahblah<br>archive<br>log config<br>hidekeys<br>!<br>!<br>crypto isakmp policy 1<br>encr 3des<br>hash md5<br>authentication pre-share<br>group 2<br>crypto isakmp key blahblahblahblah( address 82.175.38.244<br>crypto isakmp key blahblahblahblah( address 73.243.244.240<br>crypto isakmp aggressive-mode disable<br>!<br>crypto ipsec security-association lifetime kilobytes 28800<br>crypto ipsec security-association lifetime seconds 28800<br>!<br>crypto ipsec transform-set VPNSteamboat esp-3des esp-sha-hmac<br>!<br>crypto map SDM_CMAP_1 1 ipsec-isakmp<br>description Tunnel to82.175.38.244<br>set peer 82.175.38.244<br>set transform-set VPNSteamboat<br>match address 102<br>crypto map SDM_CMAP_1 2 ipsec-isakmp<br>! Incomplete<br>description Tunnel to73.243.244.240<br>set transform-set VPNSteamboat<br>match address 104<br>!<br>!<br>!<br>T1 Controllers...<br>!<br>ip tcp synwait-time 10<br>ip ssh time-out 60<br>ip ssh authentication-retries 2<br>!<br>class-map type inspect imap match-any ccp-app-imap<br>match invalid-command<br>class-map type inspect match-any ccp-cls-protocol-p2p<br>match protocol edonkey signature<br>class-map type inspect match-any HTTPS<br>match protocol https<br>class-map type inspect match-all sdm-cls-sdm-pol-NATOutsideToInside-1-2<br>match class-map HTTPS<br>match access-group name SwitchVoxHTTPS<br>class-map type inspect smtp match-any ccp-app-smtp<br>match data-length gt 5000000<br>class-map type inspect match-any PRESIP<br>match protocol sip<br>class-map type inspect match-any CCP-Voice-permit<br>match protocol h323<br>match protocol skinny<br>class-map type inspect match-all VOIPOUTMAP<br>match access-group name VOIPOUTACL<br>class-map type inspect match-any ccp-cls-insp-traffic<br>match protocol dns<br>match protocol https<br>match protocol icmp<br>match protocol imap<br>match protocol pop3<br>match protocol tcp<br>match protocol udp<br>class-map type inspect match-all ccp-insp-traffic<br>match class-map ccp-cls-insp-traffic<br>class-map type inspect match-any VoipOUT<br>match protocol user-Switchboard1<br>match protocol user-Switchboard2<br>match protocol user-Switchvox<br>match protocol sip<br>class-map type inspect match-all sdm-cls-ccp-inspect-1<br>match class-map VoipOUT<br>match access-group name VoIPOut<br>class-map type inspect match-any ccp-cls-protocol-im<br>match protocol ymsgr yahoo-servers<br>match protocol msnmsgr msn-servers<br>match protocol aol aol-servers<br>class-map type inspect match-all ccp-protocol-pop3<br>match protocol pop3<br>class-map type inspect match-any PREVOIP<br>match protocol sip<br>class-map type inspect pop3 match-any ccp-app-pop3<br>match invalid-command<br>class-map type inspect match-all ccp-protocol-p2p<br>match class-map ccp-cls-protocol-p2p<br>class-map type inspect match-any VOIPINMAP<br>match access-group name VOIPINACL<br>class-map type inspect match-all ccp-protocol-im<br>match class-map ccp-cls-protocol-im<br>class-map type inspect match-all ccp-invalid-src<br>match access-group 100<br>class-map type inspect match-all ccp-protocol-imap<br>match protocol imap<br>class-map type inspect match-any sdm-nat-https-1<br>match access-group 101<br>match protocol https<br>class-map type inspect match-all ccp-protocol-smtp<br>match protocol smtp<br>!<br>!<br>policy-map type inspect sdm-pol-NATOutsideToInside-1<br>class type inspect PREVOIP<br>pass<br>class type inspect VOIPINMAP<br>pass<br>class type inspect sdm-cls-sdm-pol-NATOutsideToInside-1-2<br>inspect<br>class type inspect sdm-nat-https-1<br>inspect<br>class class-default<br>drop<br>policy-map type inspect smtp ccp-action-smtp<br>class type inspect smtp ccp-app-smtp<br>reset<br>policy-map type inspect imap ccp-action-imap<br>class type inspect imap ccp-app-imap<br>log<br>reset<br>policy-map type inspect pop3 ccp-action-pop3<br>class type inspect pop3 ccp-app-pop3<br>log<br>reset<br>policy-map type inspect ccp-inspect<br>class type inspect PRESIP<br>pass<br>class type inspect VOIPOUTMAP<br>pass<br>class type inspect ccp-invalid-src<br>drop log<br>class type inspect ccp-protocol-smtp<br>inspect<br>service-policy smtp ccp-action-smtp<br>class type inspect ccp-protocol-imap<br>inspect<br>service-policy imap ccp-action-imap<br>class type inspect ccp-protocol-pop3<br>inspect<br>service-policy pop3 ccp-action-pop3<br>class type inspect ccp-protocol-p2p<br>drop log<br>class type inspect ccp-protocol-im<br>drop log<br>class type inspect sdm-cls-ccp-inspect-1<br>pass<br>class type inspect ccp-insp-traffic<br>inspect<br>class type inspect CCP-Voice-permit<br>inspect<br>class class-default<br>pass<br>!<br>zone security out-zone<br>zone security in-zone<br>zone-pair security sdm-zp-NATOutsideToInside-1 source out-zone destination in-zone<br>service-policy type inspect sdm-pol-NATOutsideToInside-1<br>zone-pair security ccp-zp-in-out source in-zone destination out-zone<br>service-policy type inspect ccp-inspect<br>!<br>!<br>!<br>interface Null0<br>no ip unreachables<br>!<br>interface Multilink1<br>description $FW_OUTSIDE$<br>ip address 73.243.75.99 255.255.255.240 secondary<br>ip address 73.243.75.100 255.255.255.240 secondary<br>ip address 73.243.75.101 255.255.255.240 secondary<br>ip address 73.243.75.98 255.255.255.240<br>no ip redirects<br>no ip unreachables<br>no ip proxy-arp<br>ip nat outside<br>no ip virtual-reassembly<br>zone-member security out-zone<br>no cdp enable<br>ppp multilink<br>ppp multilink group 1<br>crypto map SDM_CMAP_1<br>!<br>interface GigabitEthernet0/0<br>description $ETH-SW-LAUNCH$$INTF-INFO-GE 0/0$$ES_LAN$$FW_INSIDE$$ETH-LAN$<br>ip address 10.10.20.1 255.255.255.0<br>no ip redirects<br>no ip unreachables<br>no ip proxy-arp<br>ip nat inside<br>ip virtual-reassembly<br>zone-member security in-zone<br>duplex auto<br>speed auto<br>no cdp enable<br>no mop enabled<br>!<br>::Serial and unused interfaces::<br>!<br>ip local pool SSLPOOL 10.10.20.30 10.10.20.40<br>ip forward-protocol nd<br>ip route 0.0.0.0 0.0.0.0 73.243.75.97<br>ip http server<br>ip http access-class 2<br>ip http authentication local<br>ip http secure-server<br>ip http timeout-policy idle 60 life 86400 requests 10000<br>!<br>!<br>ip nat inside source route-map SDM_RMAP_1 interface Multilink1 overload<br>ip nat inside source static 10.10.20.5 73.243.75.99<br>ip nat inside source static 10.10.20.210 73.243.75.100<br>!<br>ip access-list extended SwitchVoxHTTPS<br>remark CCP_ACL Category=128<br>permit ip any host 10.10.20.5<br>ip access-list extended VOIPINACL<br>permit tcp any host 10.10.20.5 eq 5222<br>permit tcp any host 10.10.20.5 eq 843<br>permit tcp any host 10.10.20.5 eq 5060<br>permit udp any host 10.10.20.5 eq 5060<br>permit udp any host 10.10.20.5 range 10000 10500<br>ip access-list extended VOIPOUTACL<br>permit tcp host 10.10.20.5 eq 5222 any<br>permit tcp host 10.10.20.5 eq 843 any<br>permit tcp host 10.10.20.5 eq 5060 any<br>permit udp host 10.10.20.5 any eq 5060<br>permit udp host 10.10.20.5 any range 10000 10500<br>ip access-list extended VoIPOut<br>remark CCP_ACL Category=128<br>permit ip host 10.10.20.5 any<br>!<br>no logging trap<br>access-list 2 remark HTTP Access-class list<br>access-list 2 remark CCP_ACL Category=1<br>access-list 2 permit 10.10.20.0 0.0.0.255<br>access-list 2 deny any<br>access-list 100 remark CCP_ACL Category=128<br>access-list 100 permit ip host 255.255.255.255 any<br>access-list 100 permit ip 127.0.0.0 0.255.255.255 any<br>access-list 100 permit ip 73.243.75.96 0.0.0.15 any<br>access-list 101 remark CCP_ACL Category=0<br>access-list 101 permit ip any host 10.10.20.210<br>access-list 101 permit ip 192.168.11.0 0.0.0.255 10.10.20.0 0.0.0.255<br>access-list 101 permit esp 192.168.11.0 0.0.0.255 10.10.20.0 0.0.0.255<br>access-list 101 permit ip 192.168.111.0 0.0.0.255 10.10.20.0 0.0.0.255<br>access-list 101 permit esp 192.168.111.0 0.0.0.255 10.10.20.0 0.0.0.255<br>access-list 102 remark CCP_ACL Category=4<br>access-list 102 remark IPSec Rule<br>access-list 102 permit ip 10.10.20.0 0.0.0.255 192.168.111.0 0.0.0.255<br>access-list 104 permit ip 10.10.20.0 0.0.0.255 192.168.0.0 0.0.0.255<br>access-list 105 deny ip any 10.10.30.0 0.0.0.255<br>access-list 105 remark CCP_ACL Category=2<br>access-list 105 deny ip 10.10.20.0 0.0.0.255 192.168.0.0 0.0.0.255<br>access-list 105 remark IPSec Rule<br>access-list 105 deny ip 10.10.20.0 0.0.0.255 192.168.111.0 0.0.0.255<br>access-list 105 permit ip 10.10.20.0 0.0.0.255 any<br>access-list 120 permit ip host 10.10.27.67 host 192.168.111.30<br>access-list 120 permit ip host 192.168.111.30 host 10.10.27.67<br>access-list 150 permit ip host 10.10.30.30 host 10.10.20.67<br>access-list 150 permit ip host 10.10.20.67 host 10.10.30.30<br>access-list 198 permit udp host 73.243.75.98 host 82.175.38.244 eq isakmp<br>access-list 198 permit udp host 82.175.38.244 eq isakmp host 73.243.75.98<br>access-list 199 permit ip 10.10.20.0 0.0.0.255 192.168.111.0 0.0.0.255<br>access-list 199 permit ip 192.168.111.0 0.0.0.255 10.10.20.0 0.0.0.255<br>no cdp run<br><br>!<br>!<br>!<br>route-map SDM_RMAP_1 permit 1<br>match ip address 105<br>!<br>!<br>radius-server host 10.10.20.200 auth-port 1645 acct-port 1646 key 7 062636234D4C5B0C44<br>!<br>control-plane<br>!<br>banner exec &#3;<br>% Password expiration warning.<br>-----------------------------------------------------------------------<br>-----------------------------------------------------------------------<br>&#3;<br>banner login &#3;Authorized access only!<br>Disconnect IMMEDIATELY if you are not an authorized user!&#3;<br>!<br>line con 0<br>login authentication local_authen<br>transport output telnet<br>line aux 0<br>login authentication local_authen<br>transport output telnet<br>line vty 0 4<br>login authentication LOCAL<br>transport input all<br>line vty 5 15<br>login authentication LOCAL<br>transport input all<br>!<br>scheduler allocate 20000 1000<br>!<br>webvpn gateway SSL<br>ip address 73.243.75.98 port 443<br>ssl trustpoint SSLCERT<br>inservice<br>!<br>webvpn install svc flash:/webvpn/anyconnect-win-2.3.2016-k9.pkg sequence 1<br>!<br>webvpn context SSL<br>secondary-color white<br>title-color #CCCC66<br>text-color black<br>ssl authenticate verify all<br>!<br>!<br>policy group SSL_Policy<br>functions svc-enabled<br>svc address-pool "SSLPOOL"<br>svc default-domain "domain.local"<br>svc keep-client-installed<br>svc split include 10.10.20.0 255.255.255.0<br>svc dns-server primary 10.10.20.200<br>default-group-policy SSL_Policy<br>aaa authentication list local_authen<br>gateway SSL<br>inservice<br>!<br>end<br><br>Thank you in advance, all input is greatly appreciated!<br><br>-Pasta]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Config-Cisco-2821-Router-Firewall-Mysteriously-Dropped-Packe-23107745</guid>
<pubDate>Wed, 30 Sep 2009 13:54:00 EDT</pubDate>
</item>

</channel>
</rss>
