ASA 8.02 and TCP Urgent flag

Unanswered Question
Feb 21st, 2008
User Badges:

I recently upgraded a customer from a PIX 525 (running 7.0 code) to a pair of ASA 5550s in active/standby mode. The ASA runs 8.02. The customer uses a software identity service called Trusted Network Technologies 'Identity', which communicates with a server on the outside of the firewall. The software requires that TCP sequence number randomization be turned off, and that the TCP Urgent flag status is preserved through the firewall.


After upgrading to the ASA, the TNT software no longer functions. The software vendor is telling me that there may be some conflicts in the ACLs used for NAT and the TCP map.


Here is the portion of the config that I believe to be relevant. Any ideas?


access-list global_mpc extended permit ip any y.y.0.0 255.255.0.0


class-map OCDE-class

match access-list global_mpc

!

policy-map global-policy

class OCDE-class

set connection random-sequence-number disable

set connection advanced-options OCDE-map


tcp-map OCDE-map

urgent-flag allow


global (outside) 101 x.x.x.127 netmask 255.255.255.0

global (outside) 103 x.x.x.129 netmask 255.255.255.0


nat (inside) 103 access-list inside_nat_outbound norandomseq

nat (inside) 101 0.0.0.0 0.0.0.0

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.

Actions

This Discussion