<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CCIE Security &#8211; Cisco ASA Modular Policy Framework Example</title>
	<atom:link href="http://blogg.kvistofta.nu/ccie-security-cisco-asa-modular-policy-framework-example/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogg.kvistofta.nu/ccie-security-cisco-asa-modular-policy-framework-example/</link>
	<description>A Cisco Security-guy exploring the world</description>
	<lastBuildDate>Mon, 03 May 2010 22:24:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Jimmy Larsson</title>
		<link>http://blogg.kvistofta.nu/ccie-security-cisco-asa-modular-policy-framework-example/comment-page-1/#comment-73</link>
		<dc:creator>Jimmy Larsson</dc:creator>
		<pubDate>Fri, 08 Jan 2010 00:50:16 +0000</pubDate>
		<guid isPermaLink="false">http://blogg.kvistofta.nu/?p=564#comment-73</guid>
		<description>One strange thing with my example above is that if I modify the access-list to define all ip or tcp-traffic from the host (that is: remove &quot;eq ftp&quot;) it will kill most traffic from the host, including http and dns-traffic. It also logs the events like this:&lt;br&gt;&lt;br&gt;%ASA-5-303004: FTP GET /x/331 command unsupported - failed strict inspection, terminating connection from inside:192.168.1.215/2597 to outside:69.63.178.129/80&lt;br&gt;%ASA-4-507003: tcp flow from inside:192.168.1.215/2597 to outside:69.63.178.129/80 terminated by inspection engine, reason - inspector drop reset.&lt;br&gt;%ASA-5-304001: 192.168.1.50 Accessed URL 69.63.178.129:/x/1545766483/false/p_723103014=14&lt;br&gt;%ASA-5-303004: FTP GET /x/363 command unsupported - failed strict inspection, terminating connection from inside:192.168.1.215/2598 to outside:69.63.178.129/80&lt;br&gt;%ASA-5-304001: 192.168.1.50 Accessed URL 69.63.178.129:/x/2682102391/false/p_723103014=15&lt;br&gt;%ASA-5-304001: 192.168.1.215 Accessed URL 69.63.187.17:/ajax/presence/reconnect.php?reason=1&amp;iframe_loaded=true&amp;post_form_id=64034a00a11a87e6c77c6c1c66a71bea&amp;__a=1&lt;br&gt;%ASA-5-303004: FTP GET /x/893 command unsupported - failed strict inspection, terminating connection from inside:192.168.1.215/2599 to outside:69.63.178.129/80&lt;br&gt;%ASA-4-507003: tcp flow from inside:192.168.1.215/2599 to outside:69.63.178.129/80 terminated by inspection engine, reason - inspector drop reset.&lt;br&gt;&lt;br&gt;So far I cant explain why. If someone knows, please tell me!</description>
		<content:encoded><![CDATA[<p>One strange thing with my example above is that if I modify the access-list to define all ip or tcp-traffic from the host (that is: remove &#8220;eq ftp&#8221;) it will kill most traffic from the host, including http and dns-traffic. It also logs the events like this:</p>
<p>%ASA-5-303004: FTP GET /x/331 command unsupported &#8211; failed strict inspection, terminating connection from inside:192.168.1.215/2597 to outside:69.63.178.129/80<br />%ASA-4-507003: tcp flow from inside:192.168.1.215/2597 to outside:69.63.178.129/80 terminated by inspection engine, reason &#8211; inspector drop reset.<br />%ASA-5-304001: 192.168.1.50 Accessed URL 69.63.178.129:/x/1545766483/false/p_723103014=14<br />%ASA-5-303004: FTP GET /x/363 command unsupported &#8211; failed strict inspection, terminating connection from inside:192.168.1.215/2598 to outside:69.63.178.129/80<br />%ASA-5-304001: 192.168.1.50 Accessed URL 69.63.178.129:/x/2682102391/false/p_723103014=15<br />%ASA-5-304001: 192.168.1.215 Accessed URL 69.63.187.17:/ajax/presence/reconnect.php?reason=1&#038;iframe_loaded=true&#038;post_form_id=64034a00a11a87e6c77c6c1c66a71bea&#038;__a=1<br />%ASA-5-303004: FTP GET /x/893 command unsupported &#8211; failed strict inspection, terminating connection from inside:192.168.1.215/2599 to outside:69.63.178.129/80<br />%ASA-4-507003: tcp flow from inside:192.168.1.215/2599 to outside:69.63.178.129/80 terminated by inspection engine, reason &#8211; inspector drop reset.</p>
<p>So far I cant explain why. If someone knows, please tell me!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
