06-02-2009 06:41 AM - edited 03-11-2019 08:38 AM
Hi to all,
the Cisco IOS ZONE BASED Firewall support the feature "TCP Out-of-Order Packet support" ?
Regards
Roberto Taccon
Solved! Go to Solution.
11-02-2009 01:52 AM
Hi Roberto,
In the new IOS 15.0(M) ZBF already supports out-of-order TCP packets
look here:
Regards,
Tihomir Yosifov
06-02-2009 08:47 PM
This should be supported as documented with the "ip inspect tcp reassembly" command but be aware this could cause performance issues with a large number of fragmented packets.
06-03-2009 07:04 AM
Hi Pete,
thanks for the reply BUT:
1) CAN YOU CONFIRM THAT ON THE LATEST IOS VERSION THE FEATURE IS AVAILABLE / WHICH ONE / ARE THERE ANY DOCS ?
2) as indicated on the docs (for the IOS 12.4T) the Zone-based policy firewall does NOT support IT:
Restrictions for TCP Out-of-Order Packet Support for Cisco IOS Firewall and Cisco IOS IPS:
â¢The feature is enabled by default. The user must explicitly disable it. To disable TCP out-of-order packet buffering and reassembly, issue the ip inspect tcp reassembly queue length 0 command.
â¢Zone-based policy firewall is not supported. Only Cisco IOS IPS and Cisco IOS Firewall application inspection can support out-of-order TCP packets.
Regards,
Roberto Taccon
11-02-2009 01:52 AM
Hi Roberto,
In the new IOS 15.0(M) ZBF already supports out-of-order TCP packets
look here:
Regards,
Tihomir Yosifov
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide