cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5578
Views
4
Helpful
3
Replies

TCP Out-of-Order Packet support

ROBERTO TACCON
Level 4
Level 4

Hi to all,

the Cisco IOS ZONE BASED Firewall support the feature "TCP Out-of-Order Packet support" ?

https://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_out_order_fwall.html#wp1049430

Regards

Roberto Taccon

1 Accepted Solution

Accepted Solutions

Hi Roberto,

In the new IOS 15.0(M) ZBF already supports out-of-order TCP packets

look here:

http://www.cisco.com/en/US/customer/docs/ios/sec_data_plane/configuration/guide/sec_zone_polcy_firew.html

Regards,

Tihomir Yosifov

View solution in original post

3 Replies 3

plumbis
Level 7
Level 7

This should be supported as documented with the "ip inspect tcp reassembly" command but be aware this could cause performance issues with a large number of fragmented packets.

Hi Pete,

thanks for the reply BUT:

1) CAN YOU CONFIRM THAT ON THE LATEST IOS VERSION THE FEATURE IS AVAILABLE / WHICH ONE / ARE THERE ANY DOCS ?

2) as indicated on the docs (for the IOS 12.4T) the Zone-based policy firewall does NOT support IT:

Restrictions for TCP Out-of-Order Packet Support for Cisco IOS Firewall and Cisco IOS IPS:

•The feature is enabled by default. The user must explicitly disable it. To disable TCP out-of-order packet buffering and reassembly, issue the ip inspect tcp reassembly queue length 0 command.

•Zone-based policy firewall is not supported. Only Cisco IOS IPS and Cisco IOS Firewall application inspection can support out-of-order TCP packets.

https://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_out_order_fwall.html#wp1049430

Regards,

Roberto Taccon

Hi Roberto,

In the new IOS 15.0(M) ZBF already supports out-of-order TCP packets

look here:

http://www.cisco.com/en/US/customer/docs/ios/sec_data_plane/configuration/guide/sec_zone_polcy_firew.html

Regards,

Tihomir Yosifov

Review Cisco Networking products for a $25 gift card