Solved

After switching from ASA 5510 to ASA 5512 strange ack = (big number) behavior?

Posted on 2014-01-22
6
326 Views
Last Modified: 2014-02-11
After switch from ASA 5510 to ASA 5512 the internal network are acting strangely. We can't connect and print to our Konica-Minolta printers. And can't connect to WMware ESX via Sphere. Everything else seems to work OK. Our switch is a Cisco 2960S. No vLan.
The funny thing is when we connect to our hosted office server via RDP we can connect and print.
The ASA's are configured 1 to 1 as closely as possible. Latest firmware on both.
Switching back to ASA 5510 removes the problem.

We have had Cisco people looking at this, but no luck so far, except for the communication to the printer, ACK= are not 1, but a large number?

Does anyone have clue to this?
0
Comment
Question by:khc
6 Comments
 
LVL 26

Expert Comment

by:Soulja
ID: 39800117
Can you post both fw configs as well as the switch? Please attach them to the post instead of pasting them.
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 39800304
ACK being a large value doesn't mean anything.  I'm assuming you're talking about seeing it in wireshark maybe.  could happen if it doesn't know where the sequence numbers started depending on when the capture was started so it doesn't know the relative number to the starting point.

But as Soulja commented, the configs would help.
0
 
LVL 12

Expert Comment

by:Henk van Achterberg
ID: 39800891
How is your NAT config?

Are you sure that ProxyArp is not messing things up?

When you are on the same network traffic should not flow trough the ASA when connecting internally.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 26

Expert Comment

by:Soulja
ID: 39800959
Until configs are provided, we can only make assumptions.
0
 

Author Comment

by:khc
ID: 39804334
Thank you for answering. Here are the configs for ASA 5510 and ASA 5512.
ASA5510-5512runningconfig.txt
0
 
LVL 18

Accepted Solution

by:
Akinsd earned 500 total points
ID: 39829007
I probably would recommend a packet trace to identify where the packets are dropping

- packet-tracer input inside tcp 192.168.118.x 4444 192.168.118.x 4444 detailed

You can also use Examdiff to compare both configs to determine if a command is missing or a new command is introduced
http://www.prestosoft.com/edp_examdiff.asp

Also, check if aaa authentication is enabled on the switch or any acl that may be filtering traffic based on MAC address
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
SSH commands for Nas4free 21 304
Backup UPS - email alert 3 86
USB System Failing 17 60
Xymon customize http timeout 2 32
If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now