C65K ASA module - syn cookie & ASAx clustering (9.x)

Hi,
A couple of questions:
I want to move syn cookie protection from ACE-modules to ASA modules in a data center setup. And I want to set a max embryonic conns per server/IP behind the firewall f.ex 512/server
Acc to the ASA conf.guide 8.5 you can make and apply a service-policy f.ex to the outside interface with the following variables (among others):
- conn-max (0-2000000). I suppose this i an overall 'conns through the box' value ?
- embryonic-conn-max n. Is n the overall embryonic 'conns through the box' value ?
- per-client-embryonic-max If clients are outside-hosts accessing an inside-server, it will not mitigate dDoS syn-attacks very well, will it ?
Apparantly none of the above settings limit embryonic conns per inside server ?
On the other hand the configuration guide says:
When you use TCP SYN cookie protection to protect servers from SYN attacks, you must set the embryonic connection limit lower than the TCP SYN backlog queue on the server that you want to protect. Otherwise, valid clients can nolonger access the server during a SYN attack.
And to something completely different:
In 9 ASA software clustering of 5585-x is an option. Does it apply to the ASA modules as well, (which are based on the 5585-x) ?
Thanks
Regards Jesper Joensen

Iyer
Agree - but you still have a problem with heavy dDoS attacks with thousands of spoofed IPs.
I ended up with this config (going into production very soon) - the embryonic-conn-max 512 is intended to trig syn-cookies during syn-attacks:
class-map EMBRYONIC-CONNS
match any
policy-map EMBRYONIC-CONNS
class EMBRYONIC-CONNS
  set connection embryonic-conn-max 512 per-client-embryonic-max 5
service-policy EMBRYONIC-CONNS interface msfc
Thanks
Jesper

Similar Messages

  • Difference in ASA module, ASA 5510

    Folks,
    I am trying to get some comparison good data on the Cisco ASA(5585 probably) module and the Cisco 5510 physical device.
    We are looking to create contexts and most of these contexts are dynamic in nature.
    What could be the advantages and disadvantages of using one and the other.
    I know the ASA 5510 supports virtual contexts but not sure how much are supported by the base license and how much could be added.
    Futher the communication between the Switch and the ASA module goes via the backplane and in case of physical device will go over the LAN cable(mostly a 1Gig). Will this be slower?
    Regards,
    Nikhil.

    Hi,
    Check if the below datasheet helps..
    http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html
    hth
    MS

  • Cisco 6500 ASA Module

    Greetings,
    I have 6509-E switch with Cisco ASA module, I have two network segments 1. 10.60.5.0/24        2. 10.60.6.0/24, the ASA module is gateway for my two subnets, routing protocol is cisco EIGRP, everything looks normal, but when I am trying to copy files from one computer which has the IP 10.60.6.21 to another computer which has the IP 10.60.5.100 in another network subnet, they latency goes high and copying is very slow.
    Please help me.

    Hi,
    I think the easiest test would be to check for any inspections for the traffic that you are using for the test on the ASA device.
    Also , you can try this:-
    http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/111986-asa-tcp-bypass-00.html
    Thanks and Regards,
    Vibhor Amrodia

  • 6500 with ASA module

    Hello guys,
    I'm designing small-medium branch office (from 100 users scalable up to 500).
    My idea was to build this around a pair of 6506-E switches (as collapsed core, utilizing VSS), then at each floor (1 floor = 100 users) have a stack of 3750 switches.
    Now, to my question, I want a pair of security appliances, one per each breakout. I was looking at a possibility of putting ASA module into each 6500.
    Is it possible, to use 10G X2 module, which are build into 6500's SUP as WAN interface and direct everything it receives on those ports directly into ASA? (I want to have all traffic which will come to the 6500 via SUP's X2 modules to pass through ASA before any further action will be taken).
    As fair as I know in order to use VSS together with ASA modules in active/active mode (I will load balance through uplinks on both 6500) I need to use SUP 720-10G, am I right?
    Thanks in advance for you insights.
    Michal

    Thanks guys. Appreciate your feedback!
    I will most likely go  for the option "Existing ASA 5540 with IPS module" . I hope the IPS module does not limit any bandwidth capability or processing issue of the ASA. My current throughput is 250 Mbps bidirectional.
    After looking at the IPS option I am sloghly confused which one I need. Cisco website say:
    "...adding the broad range of intrusion prevention and advanced antiworm services delivered by the IPS modules via the AIP SSM and AIP SSC, or the comprehensive malware protection and content security services enabled by the CSC SSM."
    Do I need SSM only or both SSM and SSC or CSC SSM? How many module cana be installed on 5540?
    Fawad

  • How do you session to asa module on 6509?

    I have a new 6509 ASA Module. When i try and open a session, fails. here are the outputs.
     1    3  ASA Service Module                     WS-SVC-ASA-SM1     SAL1813P1P8
      2    4  WiSM 2 WLAN Service Module             WS-SVC-WISM2-K9    SAL1815QD32
      3   48  CEF720 48 port 10/100/1000mb Ethernet  WS-X6848-GE-TX     SAL1814PFAK
      4   48  CEF720 48 port 1000mb SFP              WS-X6848-SFP       SAL1815QBQT
      5    5  Supervisor Engine 2T 10GE w/ CTS (Acti VS-SUP2T-10G       SAL1815QCZE
    Mod MAC addresses                       Hw    Fw           Sw           Status
      1  4c00.826a.32b4 to 4c00.826a.32c3   2.0   12.2(50r)SYL 15.0(1)SY6   Ok
      2  30f7.0d0b.f630 to 30f7.0d0b.f63f   1.1   12.2(18r)S1  15.0(1)SY6   Ok
      3  a80c.0df1.edd0 to a80c.0df1.edff   1.0   12.2(18r)S1  15.0(1)SY6   Ok
      4  18e7.2820.4c00 to 18e7.2820.4c2f   3.0   12.2(18r)S1  15.0(1)SY6   Ok
      5  6c41.6a0c.17d2 to 6c41.6a0c.17d9   1.7   12.2(50r)SYS 15.0(1)SY6   Ok
    Mod  Sub-Module                  Model              Serial       Hw     Status
     1/0 ASA Application Processor   SVC-APP-PROC-1     SAL1808MGPL  1.0    Ok
      3  Distributed Forwarding Card WS-F6K-DFC4-A      SAL1813PD2L  2.0    Ok
      4  Distributed Forwarding Card WS-F6K-DFC4-A      SAL1815PY3J  2.0    Ok
      5  Policy Feature Card 4       VS-F6K-PFC4        SAL1814PLKQ  2.1    Ok
      5  CPU Daughterboard           VS-F6K-MSFC5       SAL1815Q2ZZ  2.1    Ok
    all modules loaded up ok.
    sess slot 1 pro 1
    The default escape character is Ctrl-^, then x.
    You can also type 'exit' at the remote prompt to end the session
    Trying 127.0.0.11 ...
    % Connection timed out; remote host not responding

    Try "service-module session slot 1". Reference.

  • Function modules to read Time clusters B1 and B2 from PCL1 and PCL2

    Hi All
    Are there any function modules or macros to read time clusters B1 & B2?
    I want to read time data in the clusters for reporting purpose.
    Regards,
    Rupesh Mhatre

    You can also call the FM HR_TIME_RESULTS_GET and get the exact cluster you need from B2 like WPBP, ZE, SALDO etc.
    Otherwise if you want to use the older FM declare the GET_TBUFF and GET_BUFFER_DIR as of below structure.
    DATA: BEGIN OF TBUFF OCCURS 5000.                           "XPMK014785
            INCLUDE STRUCTURE PCL1.
            DATA: SGART(2),
          END OF TBUFF.
    DATA: BEGIN OF BUFFER_DIR OCCURS 2000,                      "XPMK014785
            SGART(2),
            CLIENT LIKE PCL1-CLIENT,
            RELID LIKE PCL1-RELID,
            SRTFD LIKE PCL1-SRTFD,
            NTABX LIKE SY-TABIX, "pointer auf aktuellen satz
            OTABX LIKE SY-TABIX, "pointer auf alten satz (falls vorhanden)
            NNUXT LIKE PCL1-SRTF2, "anzahl folgesaetze aktueller Satz
            ONUXT LIKE PCL1-SRTF2, "anzahl folgesaetze alter Satz
          ofset(3) type p,     "offset innerhalb eines entry
          END OF BUFFER_DIR.
    INT_TIME_RESULTS should be of type PTM_TIME_RESULTS.
    Regards
    Ranganath

  • Help required in creating function module which reads payroll clusters.

    Hi ,
    We have a requirement where in we need to create a function module for reading a sequence of tables from payroll clusters. This function module does two functions:
    1.Read the payroll results from one system.
    2.write the payroll results to other system.
    please do the needful as soon as possible.
    Thanks in advance.
    Regards,
    Durga.

    hi
    Refer to the below thread
    Programming with Clusters for HR-Payroll
    Regards
    Sameer

  • Manually configuring ASA modules vs discovering them

    We're starting to deploy ASA now to replace some aging / end of life devices (PIX and IDS sensors).  Once the network admins set up the required IDS module(s) etc. on the ASA, I can then configure each of them as reporting devices in MARS (I can also discover the individual settings on the IPS e.g. virtual sensors ).  Basically looks just like an IPS v7 box.
    Question: should I first set up the ASA itself in MARS, and then use the discover feature top-down for MARS to uncover the IPS, firewall modules etc. -  as opposed to configuring each module individually as a reporting device in MARS?  Aside from the add'l effort required, are there any distinct advantages or issues with one method vs the other?  What are the gotcha's if we ignore the ASA (from MARS perspective) and treat all modules individually - i.e. MARS would have no knowlege of the ASA itself, and considers the modules to be all "stand alone" in that respect...?
    hope that makes sense
    thanks

    Hello,
    You could use either methods and both of them are absolutely fine. There are no specific gotchas if you add the modules individually just that it is a little more work and it is absolutely fine to have the modules configured individually on the MARS.
    Hope this clarifies!!
    Thanks,
    --Sunil

  • IOS IDS vs. ASA Module vs. ISR module vs. Blade vs. Appliance

    Hello!
    does anyone have any matrix or reference of performance, but also features and functionalities comparison for really the entire IPD solution for Cisco?

    IOS (software-based) IDS is not an option at all, so far as performance/functionality is concerned. Performance ratings are provided by cisco.com: http://www.cisco.com/go/ips for both blades and appliances. And they all have almost (99%) identical features, because use the same software. The difference, however, is how they capture traffic from the net.

  • Does ASA Service Module on 6509-E support Remote Access VPN ?

    I'm having a problem configuring Remote Access VPN (SSL, Anyconnect ect.) on ASA Service Module on 6509-E. Is this even supported  or am i wasting my time trying to make something work which will not work in a first place :) ? Site-to-Site works without any problems.
    Tech Info:
    6509-E running SUP 2T 15.1(2)SY
    ASA Module - WS-SVC-ASA-SM1 running image - asa912-smp-k8 & asdm-712
    Licenses on ASA:
    Encryption-DES - Enabled
    Encryption-3DES-AES  -Enabled
    Thanks in Advance for support.

    Are you running multiple context mode?
    If you are, remote access VPN is not supported in that case:
    "Note Multiple context mode only applies to IKEv2 and IKEv1 site to site and does not apply to AnyConnect, clientless SSL VPN, the legacy Cisco VPN client, the Apple native VPN client, the Microsoft native VPN client, or cTCP for IKEv1 IPsec."
    Reference.

  • ASA: set connection embryonic-conn-max

    Hi
    In order to mitigate syn-floods, syn-cookies are usefull tools, but I wonder how the count is.
    F.ex if this security police from the configuration guide is applied to the outside interface:
    hostname(config)# class-map CONNS
    hostname(config-cmap)# match any
    hostname(config-cmap)# policy-map CONNS
    hostname(config-pmap)# class CONNS
    hostname(config-pmap-c)# set connection conn-max 1000 embryonic-conn-max 3000
    hostname(config-pmap-c)# set connection timeout idle 2:0:0 embryonic 0:40:0 half-closed
    0:20:0 dcd
    hostname(config-pmap-c)# service-policy CONNS interface outside
    the syn-cookie/tcp-intercept will kick in when 3000 embryonic conns are seen from the outside, but is the count per ASA-box/module / per context og per IP-address   ?
    Thanks :-)
    Jesper Joensen

    Hello Jesper,
    Regarding your question. Since you are using the commands:
    conn-max n argument  sets the maximum number of simultaneous TCP and/or UDP connections that  are allowed, between 0 and 65535. The default is 0, which allows  unlimited connections.
    embryonic-conn-max
    n argument  sets the maximum number of simultaneous embryonic connections allowed,  between 0 and 65535. The default is 0, which allows unlimited  connections.
    The count applies to the box or ASA if it is running single-context or to the specific context with the class configuration if running Multiple Context. You can also limit the connection and embryonic limit per IP by using the following commands:
    The per-client-embryonic-max n argument  sets the maximum number of simultaneous embryonic connections allowed  per client, between 0 and 65535. The default is 0, which allows  unlimited connections.
    The per-client-max n argument  sets the maximum number of simultaneous connections allowed per client,  between 0 and 65535. The default is 0, which allows unlimited  connections.
    Hope this helped you out, don't forget to rate helpful posts.
    Best Regards.
    Eddy Duran

  • Installing ASA FWSM into VSS Switches

    I am getting ready to install a pair of ASA FWSM modules (WS-SVC-ASA-SM1) into a pair of VSS 6509-E switches on our College campus network. The VSS chassis' have dual ten GigE connections to our data closets and consist of primarily wired and wireless campus network users. Apparently there several options of how to install the FWSM modules and several options of active/standby configurations in a VSS environment. I was wondering if anyone has had experience doing this and if they could share with me their experiences? And if there is a best practice for this type of deployment i.e. transparent mode vs. non-transparent mode (no NAT on these firewalls), load balancing issues, active/standby deployment, etc.? Any information would be greatly appreciated.

    There's not a whole lot of ASA Service Module deployments out there that I've seen. Most customers are opting for the 5585-X in that performance / price range.
    If you haven't already looked at it, there are some general principles outlines in the document "Service Module Design with ACE and FWSM". Much of the FWSM info there can be applied directly to the ASA SM.
    A lot depends on the environment into which they will be integrated so it's hard to answer the question in a general sense. I would say that I have seen transparent mode on perhaps 5% of the ASA implementations of any kind that I have seen.
    The ASA SM does not support clustering, so a pair is limited to HA mode. Whether you use Active/Standby or Active/Active depends partly on whether you have multiple contexts and how much complexity you feel comfortable adding.
    Hope this helps. 

  • IP Phone SSL VPN to ASA for multiple CUCM (CallManager)

    hi all,
    I have a case to support multiple CallManager clusters in different locations for internet SSL VPN IP Phone. We will deploy one ASA firewall for SSL VPN IP Phone connections. So, can we use single ASA firewall for mulitple CUCM clusters?? In order words, Internet IP Phone will connect to different CUCM via a single ASA firewall (by using SSL VPN).
    I tested I need to upload the ASA's certificate into CUCM and upload CUCM's certificate into ASA for one ASA to one CUCM. If I create multiple profile (e.g. different URL for phone logins) for different CUCM. Is it possible to do that?
    thanks for your input!
    Samuel

    Samuel,
    Did you ever find an answer to your question? I have a similar scenario.
    Any input would be appreciated.

  • Info about ASA 55xx

    Hi
    i'm starting to read about ASA 55xx in Cisco website. But after some good reading, I have some questions.....
    In Cisco Docs about ASA55xx, I see the "Maximum concurrent AnyConnect or clientless VPN sessions" and "Maximum concurrent site-to-site and IPsec IKEv1 VPN sessions" (e.g. 750 both): well, the maximux concurrent sessions are 750+750 (anyconnect + site-to-site), so I have to add the two types of sessions? Or what are the maximum concurrent sessions (of each type) in ASA5520?
    So, at this point, if I want 750 AnyConnect Session and 750 site-to-site Session which license do i need to buy? ASA5500-SSL-750 ? ASA-VPNS-1000? or whatelse?
    then, what are the "shared" license? When and where do i need to buy them?
    thanks in advance.
    Bye

    Platform capabiliites and required licensing are as noted in the product data sheet:
    Up to 750 AnyConnect and/or clientless VPN peers can be supported on each Cisco ASA 5520 by installing an Essential or a Premium AnyConnect VPN license; 750 IPsec VPN peers are supported on the base platform. VPN capacity and resiliency can be increased by taking advantage of the Cisco ASA 5520's integrated VPN clustering and load-balancing capabilities. The Cisco ASA 5520 supports up to 10 appliances in a cluster, offering a maximum of 7500 AnyConnect and/or clientless VPN peers or 7500 IPsec VPN peers per cluster.
    Reiterating:
    The ASA 5520 750 site-site VPN capability is in the base license / product (Part number ASA5520-BUN-K9 or  ASA5520-K8 depending on whther you are eleigible to pruchase the strong encryption (-BUN-K9) version)
    The AnyConnect user licenses required depend on whether you need Anyconnect Essentials or Premium. The Anyconnect data sheet outlines the differences. Essentials is one license that allows up to 750 clients to use the appliance simultaneously. Premium (which cannot be loaded at the same time as Essentials) requires the licenses to be purchased according to the tiered per user scheme.
    Shared licenses are shared among ASAs in a cluster (2 or more units configured together).
    There is the concept of licenses in a failover (2-unit) cluster. That is automatic - i.e. the license numbers are additive and shared up to the platform capability. the ASA5500-SSL-750 part would be used in that setup.
    There is also the concept of an anyconnect Premium Shared Server. In that scheme, the shared server allocates licenses in 50 unit blocks to the cluster membes ars they need them. The ASA-VPNS-1000 part number you mention is used in that sort of setup.

  • About application module pooling

    Hi all,
    I'm developing an application with JDev9i and I' trying to enable am pooling. I setup the jbo.recycletreshold=0 property and I put a log statement in the constructor of my Entity Object.
    I execute a query and display its result (in a paged form 10 by 10) in a jsp.
    every time I call the jsp (even when I click on the next page) I see the creation of all the entity objects. I logged applicationmodule.hashCode() and it's always the same.
    Which steps should I follow to enable am pooling with entity object pooling? I'm trying to read the pdf docs but I still haven't found what I'm looking for. Can anyone explain me what I'm doing wrong and where to find the documentation I need?
    Thanks,
    Giovanni

    Hi,
    The issue is that changing where clause parameters does not itself cause a ViewObject to re-execute its query. So,
    analyzing your code sample above:
    ApplicationModule am = cookie.useApplicationModule(true);
    Acquire an ApplicationModule instance for the session.
    ViewObject vo = am.findViewObject("DoctorView");
    vo.setWhereClause("ID_DOC = :1");
    vo.setWhereClauseParams(new Object[]{new oracle.jbo.domain.Number(1160)});
    // tag0
    Find the target ViewObject and set its where clause. Do not execute the query. VO State:
    Not executed
    RowSet for ID_DOC 1160 is not fetched
    Not iterated
    RangeSize = default
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1160
    int firstIndex=0;
    int maxSize=vo.getRowCount();
    Acquire the VO's rowCount. This will force the VO to execute itself if it has not already been executed. If the VO has
    already been executed then this will not force the VO to re-execute itself. VO State:
    Executed
    RowSet for ID_DOC 1160 is fully fetched
    Not iterated
    RangeSize = default
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1160
    int rangeSize=1;
    vo.setRangeStart(0);
    vo.setRangeSize(rangeSize);
    Row[] rows=vo.getAllRowsInRange();
    Row row = rows[0];
    Setup the VO range size. VO State:
    Executed
    RowSet for ID_DOC 1160 is fully fetched
    Iterated to rowIndex 0
    RangeSize = 1
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1160
    if (row != null)
    System.out.println("IdDoc: " + row.getAttribute("IdDoc"));
    // release the application module statefully
    cookie.releaseApplicationModule(true, true);
    Release the ApplicationModule statefully. Note here that the rangeSize, the whereClause, the whereClause parameters,
    the current row, and the ViewObject's row cache will all be maintained by the ApplicationPool. VO State:
    Executed
    RowSet for ID_DOC 1160 is fully fetched
    Iterated to rowIndex 0
    RangeSize = 1
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1160
    // acquire an application module instance. use the same cookie.
    // this is equivalent to a second HTTP request originating from the same
    // session which released the cookie statefully.
    am = cookie.useApplicationModule(true);
    At this point, assuming that the AM was not recycled for use by another session (true for this SimpleTest), the same
    AM instance that was released will be returned. VO state (same as upon release):
    Executed
    RowSet for ID_DOC 1160 is fully fetched
    Iterated to rowIndex 0
    RangeSize = 1
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1160
    vo = am.findViewObject("DoctorView");
    vo.setWhereClause("ID_DOC = :1");
    vo.setWhereClauseParams(new Object[]{new oracle.jbo.domain.Number(1159)});
    // tag1
    Set the VO where clause. This is where the issue occurs. As mentioned above modifying the where clause
    parameters do not force the VO query to be re-executed. So, the VO remains in an executed, iterated state with a
    row cache corresponding to ID_DOC 1159. VO State:
    Executed
    RowSet for ID_DOC 1160 is fully fetched
    Iterated to rowIndex 0
    RangeSize = 1
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1159
    //vo.executeQuery();
    //row = vo.first();
    vo.setRangeStart(0);
    vo.setRangeSize(rangeSize);
    rows=vo.getAllRowsInRange();
    row = rows[0];
    // tag2
    Setup and populate the range. If the VO is already in an executed state then all of these operations will be performed
    against the cached RowSet (again, ID_DOC 1159). So, these will not force the VO to re-execute itself. VO State:
    Executed
    RowSet for ID_DOC 1160 is fully fetched
    Iterated to rowIndex 0
    RangeSize = 1
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1159
    if (row != null)
    System.out.println("IdDoc: " + row.getAttribute("IdDoc"));
    // release the application module statefully
    cookie.releaseApplicationModule(true, true);
    It sounds as if you would like the VO to be re-execute itself at :tag1above, placing it in the following state at :tag2:
    Executed
    RowSet for ID_DOC 1160 is fully fetched
    Iterated to rowIndex 0
    RangeSize = 1
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1160
    The most efficient way to achieve this is to force a query re-execution when the where clause parameters change.
    For example execute the following at tag0 (I assume this is the portion that simulates the servlet (model/controller) logic
    and/or at tag1 (I assume that this is the portion that simulates the JSP (view) logic which I also assume would not
    normally be responsible for setting the where clause parameter and modifying the range, correct?).
    Object[] oldWhereClauseParams = vo.getWhereClauseParams();
    // this block was copied from above tag0
    ViewObject vo = am.findViewObject("DoctorView");
    vo.setWhereClause("ID_DOC = :1");
    vo.setWhereClauseParams(new Object[]{new oracle.jbo.domain.Number(<new where clause parameter>)});
    Object[] newWhereClauseParams = vo.getWhereClauseParams();
    boolean whereClauseParamsSame =
    (newWhereClauseParams.length == oldWhereClauseParams.length);
    if (whereClauseParamsSame)
    for (int i=0; i < newWhereClauseParams.length; i++)
    if (!oldWhereClauseParams.equals(newWhereClauseParams[i]))
    whereClauseParamsSame = false;
    break;
    // force a query re-execution if the where clause paramters have changed.
    if (!whereClauseParamsSame)
    vo.executeQuery();
    which would yield the following VO state at tag2:
    Executed
    RowSet for ID_DOC 1160 is fully fetched
    Iterated to rowIndex 0
    RangeSize = 1
    User defined where clause = "ID_DOC = :1"
    Where clause parameter 0 = 1160
    Hope this helps.
    JR

Maybe you are looking for

  • Print, Export and Page Navigation Buttons in the Report

    When I view a report through CR4E, the generated report has 3 buttons namely Print, Export and Page Navigation buttons. But when I click on either of the buttons I get a 'null pointer exception'. This is a critical error as I am unable to navigate pa

  • Firefox 4.0.1 no longer recognizes pdf files

    Using Windows 7 64 bit Upgraded to Firefox 4.0.1 Can no longer open and read my PDF Bank statements. No errors, just a blank page. Removed Firefox 4.0.1 and reinstalled Firefox 3.6.17 and now everything is working right. I now can open and read my PD

  • Delay in loading webpages!

    I recently started to notice (about 2-3 days ago) that the loading of a webpage was slower than normal. I started to investigate and realized that it was just when loading a webpage and that when I tried to download something or use internet in any o

  • How Do I Delete a Reminder List from iphone 5

    I am unable to delete a reminder list which I no longer need (not an actual reminder) from my iphone 5.  I go into the menu in top lefthand corner and my reminder lists show up, but when I click on edit and swipe a reminder, no delete badge shows up,

  • Moving Objects On Button Click

    i was just woundering how to make an object e.g. (Rectangle Block) move on the click of a button     private void btn_MoveLeftMouseClicked(java.awt.event.MouseEvent evt) {         //move left     }Thanks Rich