TCP inspect and Riverbed issues

Posted on 2011-10-18
Medium Priority
Last Modified: 2012-05-12

i have recently encountered an issue when using a Cisco 1841 router with advanced security k9, and using Riverbed.

we use the built in IOS firewall feature (cbac / spi) in the router. 1 of the protocols we inspect is TCP leaving the outside interface.

Remote sites connect back to the core using IPSEC over GRE VPN tunnels. also we use Riverbed Steelhead devices at each end for data acceleration across the WAN.

Since installing an 1841 router at 1 of the remote sites, they are experiencing many instances of their site going down. i spoke to somebody who said this could be something to do with using the TCP inspect feature along with Riverbeds. apparently the router inspect feature could be blcoking the return Riverbed traffic. i find this odd because the inspect feature is enabled on the outside port only, but not against the GRE interface which the remote site traffic traverses (even though physically the GRE tunnel is out of the outside port).

has anybody seen this behaviour before, and could recommend a fix / solution.

thanks in advance.
Question by:L-Plate
LVL 20

Accepted Solution

RPPreacher earned 2000 total points
ID: 36990102

Author Comment

ID: 36991947
hi RP,

looks good my friend,

i don't suppose you have anything specific to an 1841 router or similar?

Featured Post

A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question