Cannot download from HTTP sites via Internet Explorer

Unanswered Question
Apr 19th, 2007
User Badges:

Hello, I have an issue with a newly configured ASA firewall (running v7).

From a client machine (using the ASA as the default gateway) I can download files from sites that use FTP but not from sites that use http. However, if I use Firefox (rather than Internet Explorer) I can download from FTP and HTTP without issue. General browsing works fine in all scenarios.

If I enter our proxy server details into Internet Explorer - downloading is fine also. I want to move away from this config though as the ISA proxy server is in the process of being decomissioned.

Please help

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
zulqurnain Sun, 04/22/2007 - 02:54
User Badges:
  • Bronze, 100 points or more


if you can post your config it will help solving your issue quickly.

zubairjalal Mon, 04/23/2007 - 03:06
User Badges:
  • Bronze, 100 points or more

have you tried putting the inspect on http traffic

Rex Biesty Mon, 04/23/2007 - 04:10
User Badges:

Thanks for the reply. I've added the 'inspect http' command to the global policy but alas it's made no difference.

musa19ie Tue, 04/24/2007 - 00:58
User Badges:

it seems to me that you are facing a problem with the tcp MSS, I think that your asa is dropping packets that exceed the mss advertized on the handshake phase, you can add the follwoing code to solve it:

access-list http-list permit tcp any host server_ip eq 80

class-map http

match access-list http-list

tcp-map tmap

exceed-mss allow

policy-map global_policy

class http

set connection advanced-options tmap

Rex Biesty Tue, 04/24/2007 - 01:28
User Badges:

I'm afraid that makes no difference either (just hangs on the 'file download' box)

Rex Biesty Mon, 04/30/2007 - 00:35
User Badges:

Any more takers? I can't turn off ISA until I have a resolution to this. Thanks.

Rex Biesty Mon, 04/30/2007 - 06:33
User Badges:

More info - it actually seems to be related to certain sites rather than protocols i.e. I can download from HP and Dell websites but not Microsoft (though automatic updates is working)

Rex Biesty Tue, 05/01/2007 - 23:41
User Badges:

Even more info. We use websense to filter URLs and turning off the filtering enables downloading without issue. I'll need to do a bit more digging into why this is.

gglynn Wed, 05/02/2007 - 12:18
User Badges:

We ran into this, too; it appears to be a bug with the Websense integration in earlier 7.x releases. Upgrading from 7.1(2) to 7.2(2) fixed it for us.


This Discussion