[114069] in North American Network Operators' Group
Question. Cisco PIX/ASA
daemon@ATHENA.MIT.EDU (=?iso-8859-1?B?Sm+i?=)
Wed Apr 29 18:06:51 2009
From: =?iso-8859-1?B?Sm+i?= <jbfixurpc@gmail.com>
To: "'nanog list'" <nanog@nanog.org>
Date: Wed, 29 Apr 2009 18:04:51 -0400
In-Reply-To: <9A34A79C-D973-4130-8010-0E98ECAD84F6@daork.net>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Greetings all
I have a customer running with a Cisco 5500 series firewall. What were
seeing (as a problem) is that there is a bit being flipped by the =
firewall
in the packet header. The bit in question is the Congession Window =
Reduced
or CWR bit. Under heavy load the target server is getting this bit as =
high
and since (I am guessing) its that way dropping the session yet its not =
near
capacity. It=92s a Microsoft server as well. Not that I am knocking that =
but.
Under the same situation a Linux/Apache server doesn't seem to care, and
goes about its business. Anyone heard of this? I did searches regarding =
this
but found (as per usual) tons of usless info. I'm not sure why the =
packets
are being changed by the ASA. I know there not hitting the firewall this =
way
(Packet capture) but they are getting changed. Config mishap? Is the ASA
throttling down stuff, and if so why not at the requesting party?=20
Dunno. Completely baffled. Thanks In Advance!
-Joe