Firewall Wizards mailing list archives

Re: Cisco ASA firewall: SQLnet inspection: buffer limit


From: "Christopher J. Wargaski" <wargo1 () gmail com>
Date: Thu, 15 Jan 2009 14:42:07 -0600

Hello--

Try disabling the inspection.

policy-map global_policy
 class inspection_default
  no inspect sqlnet

Your policy-map name and class name may be different.


On Thu, Jan 15, 2009 at 5:27 AM, Haim [Howard] Roman <roman () jct ac il>wrote:

Some friends have a Cisco ASA firewall, firmware version 8.0.4.  Behind the
firewall is a Oracle database.

This firewall has an SQLnet inspection feature.  However, the packet
reassembly buffer has a limit of 8 kbytes.  Many of the SQL queries are
bigger than this, and they get blocked.  Is there a way to increase this?
 (not sure how big they need).  In the meantime, they have to disable this
feature.

Thanks

--
-------------------------------------------------
Haim (Howard) Roman
Computer Center, Jerusalem College of Technology
roman () jct ac il

_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Current thread: