Inspect http issue - unable to browse secure site.

Hi,
Current version of the asa firewall is 7.1(2) in which when the inspect http is enabled, while opening secure site like axis bank account or any money market site either blank page display or page can not display error message appear. When i disable this command i am able to access all the secure sites properly. It looks like a bug but in the release not i am not finding any bug related to this issue. Please help me resolve this issue.
Amit M.

Thanks for the reply. When i disable http inspection and when i try to open login page for some of the site then this page cannot be display appear. Also i try MSS might get exceeded and found in the show asp drop tcp mss is not showing. But still i create a class for mass exceed and apply it in globle configuration but it does not work. Latter i have to disable the http inspection and it started working. Now the question is while clicking on login butten it will go from http to https page during this shifting of http to https why does it affect the connection when enable http inspection.
Following is the show asp drop output.
Please check
PIXFIREWALL# sho asp drop
Frame drop:
  Invalid IP header                                          10
  No route to host                                           13
  Reverse-path verify failed                             398846
  Flow is denied by configured rule                 107075
  Flow denied due to resource limitation          35
  Invalid SPI                                                 2
  First TCP packet not SYN                           62706
  TCP failed 3 way handshake                        1211
  TCP RST/FIN out of order                             39
  TCP packet SEQ past window                      1
  TCP invalid ACK                                          1
  TCP packet buffer full                                    209
  TCP RST/SYN in window                               14
  TCP DUP and has been ACKed                      10411
  TCP packet failed PAWS test                         10
  IPSEC tunnel is down                                     137
  IP option drop                                                551
  Expired flow                                                   26
  ICMP Inspect seq num not matched                1057
  ICMP Error Inspect different embedded conn     60
  DNS Inspect id not matched                            4674
  IPS Module requested drop                              8
  FP L2 rule drop                                               22988
  Interface is down                                             8
Flow drop:
  Flow terminated by IPS                                     16
  NAT failed                                                       13066
  Tunnel being brought up or torn down                514
  Need to start IKE negotiation                            2136
  Inspection failure                                               60

Similar Messages

  • Strange WLAN issue - can't access secure sites

    Hi!
    I've just bought a Toshiba L100-120. Everything is fine except the following.
    I can't access secure sites with the built-in Intel 3945abg device. Other sites are OK.
    If i connect LAN, everything is fine. If I insert my PCMCIA-wireless card, also everything works. The only problem is: to access secure sites with the Intel wireless device.
    I already changed the drivers, I tried everything. It's very strange :(
    Many thanks if anybody has an idea!!!!

    Hi
    Im a little bit confused. Do you mean the secured WLan or secured internet websites????
    If you cannot enter the secured, encrypted WLan you need to enter the right key.
    In other case if some websites are not displayed you could try to change the IE privacy settings for the Internet zone.

  • Unable to access secured site for some

    Greetings.
    I have setup a secured website on a 10.4 server. The site is the default page in the WebServer\Documents folder.
    I can access it fine from work and have had others access it without issue from computers at their homes using typical ISPs. However, when I try to have other access it from other locations using the same login and password, such as a business with its own networks, they are unable to connect. They get back an error message saying the password is in correct.
    Everyone can access the site when I have the security settings turned off.
    I have set up a realm to handle accessing the site. I have the following also enabled:
    WebDAV
    IP addess is set
    domain is set
    I am using Port 80
    Realm authorization is set to "Basic"
    Performance Cache is on
    I DO NOT have the following on or active:
    SSL
    SSI
    I am sure I am missing something else.
    Any input would be greatly appreciated.
    Thanks in advance for your help.

    Open the terminal window in the iMac and enter the following command:
    traceroute \[domain name here\]
    That will trace the route from your computer to their site and you will be able to see where it stops. There are a number of things that might cause this kind of problem:
    1. The website is down
    2. There's a network problem between your ISP and them
    3. They are blocking your IP address or your ISP for some reason
    4. Content filtering or the firewall in your router is blocking the website

  • Using Https to connect to a secure site with J2ME

    I have successfully been able to get a midlet using HTTPS connections to work using the J2ME wireless toolkit and following the instructions in this paper.
    http://developers.sun.com/techtopics/mobility/midp/articles/https/
    I would like to get Https working on a real device now like the Moto RAZR or Samsung A900 etc. Was wondering if someone has experience with HTtps on devices and help answer my questions.
    Would I have to use certificates issued by one of the following CAs like thawte,verisign etc and include it on the apache server and then the device would automatically install the certificate when a HTTPS connection is made to the server?
    Can self signed certificates be used on the devices , if yes how can they be imported onto the device?
    Please help.
    Thanks!

    Certificates expire by time.
    Open System Preferences > Date & Time then select the Date & Time tab.
    Make sure:  Set date and time automatically is selected.
    Now select the Time Zone tab. Select:  Set time zone automatically using current location
    Now System Preferences > Security & Privacy > Privacy
    Make sure:  Enable Location Services   is selected.

  • Using Https to connect to a secure site in J2ME

    I have successfully been able to get a midlet using HTTPS connections to work using the J2ME wireless toolkit and following the instructions in this paper.
    http://developers.sun.com/techtopics/mobility/midp/articles/https/
    I would like to get Https working on a real device now like the Moto RAZR or Samsung A900 etc. Was wondering if someone has experience with HTtps on devices and help answer my questions.
    Would I have to use certificates issued by one of the following CAs like thawte,verisign etc and include it on the apache server and then the device would automatically install the certificate when a HTTPS connection is made to the server?
    Can self signed certificates be used on the devices , if yes how can they be imported onto the device?
    Please help.
    Thanks!

    Hi jpsscott,
    I am glad to hear you resolved the issue. Thanks for sharing your experience here, it is good to other members who experience the same issue in the community. If you
    have any other questions about XCode and TFS, you can open a new thread in
    TFS- Eclipse and cross platform forum for a better response.
    Best regards,
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • Unable to connect to any secure sites with any browser

    I am unable to connect to any secure sites. I downloaded Firefox with the hopes that it would fix the problem but it did not. What ever browser I use I cant connect to any secure sites. All of the other pages load correctly.
    I have a PC notebook that I tried to load the same sites it worked fine, so I know that it is not a connecting problem.
    emac Mac OS X (10.4.6)
    ibook   Mac OS X (10.2.x)  

    Are you connecting via dial up or high speed through a router? If that latter, check the firewall settings of the router. I have my router set to medium (high, medium, low, & none) and it works most of the time. But occationally I get to sites that won't load and setting the router (temporarily) to low usually allows me to access those sites. So perhaps this is your issue.
    I think there are ways to add those sites to router security lists or "services" that will now let them through with the higher security settings, but I need it so rarely I haven't bothered to figure it out yet.
    Patrick

  • When i drag and drop an image on my site. it gives the following error. "Unable to access local files due to browser security settings. To overcome this, follo"

    I am using the firefox version 17 and when i drag and drop an image on my website. It gives me the following error.
    Unable to access local files due to browser security settings. To overcome this, follow these steps: (1) Enter "about:config" in the URL field; (2) Right click and select New->Boolean; (3) Enter "signed.applets.codebase_principal_support" (without the quotes) as a new preference name; (4) Click OK and try loading the file again. Or go to the homepage for a link to the tutorial on how to do it.
    I have completed the above steps and it is still showing the same error message. Any help would be highly appreciated.
    Thanks.

    Thanks kumars ,
    I have a specific drag and drop area on our website. This works fine for all earlier releases of Firefox after these security settings
    "(1) Enter "about:config" in the URL field; (2) Right click and select New->Boolean; (3) Enter "signed.applets.codebase_principal_support" (without the quotes) as a new preference name; (4) Click OK and try loading the file again."
    Bust these settings not work for me in Firefox 17.
    Yes the drag and drop functionality is java script based and i am not using any script blocker addons.

  • Trouble Connecting To *Certain* HTTPS (Secure) Sites

    I hope I get all the relevant info in here b/c, as will become apparent in a moment, it's a bear for me to get on here if I have to log in.
    The problems is this -- I can't get into *certain* secure sites.  I first noticed the problem a few weeks ago when I couldn't check out at Amazon, the log-in page would not come up.  Neither would any page on Amazon that is secure, i.e., requiring the entry of my password.  I can't even talk to customer service to tell them about the problem b/c I can't log in to ask my question!
    The problem has grown.  Most recently I couldn't get into Bank Of America, now I can't get into gmail.  The real kick is I couldn't get in HERE!!  (But I *can* get into my bank account, I *can* get into Chase and I *can* get into Citi, no problems.)
    The problem is occurring on both Safari and Firefox, so it's apparently not a browser issue.
    My ISP is Hughesnet, the satellite ISP.  I suspect it's a Hughes issue, but they have been no help and refuse to acknowledge the problem is theirs.
    Now, how did I get in here and why do I suspect Hughes?  Because I have a back-up dial-up ISP, Juno, and I got in here using Juno and have gotten into all of the other sites I just mentioned using Juno.  Only thing is, Juno takes eons.  I mean EONS.
    As I said, I suspect Hughes.  But, I thought I'd come here and seek help from you guys, I've received excellent and much appreciated help here in the past.  I'm hoping that I'm wrong, that it's not a Hughes problem, and that someone here can suggest a way I can correct w/e is wrong with my settings (if, in fact, it is my settings).
    Like I said, I Hope I got it all in.  I can easily come back to look at replies, but to log in to answer follow-up questions... LOL
    Thanks in advance for your help!

    I'm having this problem as well - and it is indeed very frustrating.  I think it started about two weeks ago (but I've been gone for 10 days during that period).  I couldn’t log in with my passwords to amazon.com, iTunes, or TD Bank.  All were https sites (but other https sites like apple.com worked – go figure)  It does seem to be a "site issue" with Hughes.
    I spent hours talking with senior AppleCare IT folks and Hughes tech support over the weekend. The Hughes person "escalated" my issue to "the highest advanced tech support" at Hughes, and I got a call back today. They said they are starting to hear from other customers, and their Engineers are working on it.  They don't know when it will be fixed.
    At least it does not appear to be a virus, which was my concern.  Hopefully Hughes will resolve this soon (but they are not exactly the best about customer service).  Still, I live in a rural area and the Hughes satellite is better than dial up.
    Hope this helps (at least you know one other person can relate!)

  • Cisco RV042 - Dual Wan Load Balancing - Secure Site (HTTPS) Trouble

    PID VID :
    RV042 V03
    Firmware Version :
    v4.0.0.07-tm (Aug 19 2010 19:19:50)
    Ever since I setup my RV042 with load balancing using the Dual Wan system I have had trouble staying connected to some secure sites. After doing some searching I found that the potential issue is the IP change mid session.
    "http://www.broadbandreports.com/forum/r25537589-Cisco-RV042-can-not-use-load-balancing-for-some-web-sites"
    Although my interface is significantly different I was able to find the same area in my RV042 admin area however, it doesn't seem to work.
    System Management
    > Dual Wan
    In Wan 1 & Wan 2 I have HTTPS and HTTPS Secondary all forwarded to use Wan 2 under Protocol Binding
    This however has not managed to do anything at all for my network and every computer conneceted experiences the same HTTPS irregularities at some websites.
    I'm sure I must be doing something wrong, but I don't know what it is.
    Both incoming connections are from the same service provider although the plans are different.
    Any help with this would greatly help me stop losing my mind trying to fight with my website control panel for 10 minutes to just login and get something done.
    Thanks

    Any ideas or advice from anyone?

  • Some secure sites recommend closing the browser. Is closing the tab the same as closing the browser?

    Secure sites recommend closing the browser. Is closing just the tab effectively the same?

    you can try disabling ipv6 support in firefox & see if that helps - [https://support.mozilla.org/en-US/kb/Server%20not%20found#w_ipv6]

  • HT4884 When attempting to log into a secured site that I have used before it tell me javascrip to be enables on browser

    I am trying to use a secured site that I have used in the past, it now tells me that the Javascript for this site is to be enabled.  Yet when I go into the systems preferences is is already checked.  Can you help me

    1.6.0_29 has an SSL bug in it and it has been fixed in 1.6.0_30 but Apple hasn't released it yet. 
    http://www.oracle.com/technetwork/java/javase/6u30-relnotes-1394870.html
    I just fixed my Windows VM.  I was having problems connecting to SQL Server through JDBC with 1.6.0_29 but works perfectly with 1.6.0_30.

  • HH3 slowing down on https secure sites

    Hi I'm not too technically minded so this may be straight forward and I'm missing something obvious so hopefully someone can point me in the right direction. I had posted the issue here before with limited response so tried the tech team via email but that seems to have stalled. My connection is c6 MB and that's fine for where I am. All sites load quickly except for any sort of secure site - payments, membership log ins etc. It happens on 3 different devices running 3 different browsers and with 2 wireless and 1 Ethernet so I'm pretty confident it's in the hub or somewhere earlier in the chain ( but I may well be wrong). If I turn off the hub it clears the problem for a few days maybe a week but then the problem slowly returns with secure sites loading slower and slower until they eventually time out. Whilst it is annoying to have to keep turning it on and off it's more annoying when going through payment processes and then at the last hurdle it alls over or you're not sure if it's completed properly or not. The HH3 is c3 months old and our previous HH2 showed similar behaviour but not quie as often. The response to my previous post reckoned something to do with DNS(?) which is when I tried to raise it with the tech email. I had previously tried the live chat on the BT site but after having been dumped out of chats twice and the responses taking over half an hour at a time this wasn't working as an effective route for me. Any ideas?!

    Hi John I'm not sure how I would go about changing the dns settings and what to? The bit I don't understand is why it happens on 3 different devices all running different browsers and different firewall packages at the same time. Resetting the hub by turning off and on clears the issue on all 3 devices at the same time without changing any setting on the PF, laptop or iPad. They then all start to show the same behaviour at the same time when it redevelops in a few days time. I can't see how they can all gang p on me at the same time and the decide to clear the problem simultaneously, the only common factor seeming to me to be the hub. How might I change dns in a HH3- is it in advanced settings and is there somewhere I can find that would show me the sort of settings they can change to? Lots of q I know and I appreciate I'm not as IT literates I should be so apologies if the above sounds like an idiot (because it is) Thanks for any help.

  • The lock symbol is missing on secure sites and there is no back arrow after browsing

    I don't like the new toolbar after upgrading firefox.
    1. there is no back button to get out of a page
    2. the secure lock symbol is missing on secure sites
    Please help with changing these 2 problems

    In Firefox 4 and later you no longer have the Status bar that showed the padlock in previous Firefox versions.<br />
    The padlock only shows that there is a secure connection and doesn't guarantee that you are connected to the right server.<br />
    So you might still be connected to the wrong server if you make a typo in the URL and someone has claimed that mistyped URL.<br />
    The functionality of the padlock has been replaced by the [[Site Identity Button]] on the left end of the location bar.
    See also:
    * http://www.dria.org/wordpress/archives/2008/05/06/635/
    * https://support.mozilla.org/kb/Site+Identity+Button
    If the menu bar is hidden then press the F10 key or hold down the Alt key to make the menu bar appear.
    Make sure that toolbars like the "Navigation Toolbar" and the "Bookmarks Toolbar" are visible: "View > Toolbars"
    *Open the Customize window via "View > Toolbars > Customize"
    *Check that the "Bookmarks Toolbar items" is on the Bookmarks Toolbar
    *If the "Bookmarks Toolbar items" is not on the Bookmarks Toolbar then drag it back from the toolbar palette in the customize window to the Bookmarks Toolbar
    *If missing items are in the toolbar palette then drag them back from the Customize window on the toolbar
    *If you do not see an item on a toolbar and in the toolbar palette then click the "Restore Default Set" button to restore the default toolbar set up
    *http://kb.mozillazine.org/Toolbar_customization
    *https://support.mozilla.org/kb/Back+and+forward+or+other+toolbar+items+are+missing
    The arrow to open the tab history of the Back and Forward buttons has been removed in Firefox 4 and later.<br />
    Use one of these methods to open the tab history list:
    * Right click on the Back or Forward button
    * Hold down the left mouse button on the enabled Back or Forward button until the list opens

  • Firefox 20.0 doesn't work for secure sites - it hangs up. Just upgraded to Mountain Lion.

    I try to login to a secure site, but Firefox 20.0 doesn't return the login page. The busy wheel just goes around and around for a long time, but nothing happens.

    Hello sonyashannon, you can't login to a specific secure site, you can't connect to any secure site ?
    see : [https://support.mozilla.org/en-US/kb/fix-login-issues-on-websites-require-passwords#os=mac&browser=fx20 Fix login issues on websites that require a username and password]
    thank you

  • Unable to browse mysite in SharePoint 2013

    HI All,
    I Configured MySite in SharePoint2013,once i clicking on News feed i am getting access required "Let us know why you need access to this site. " i am unable to browse the MySite,but i can able to access only from farm service account only.
    Can any one help on this. Configuration every thing is fine.

    Check the following things:
    1)You have included wild card inclusion for web application
    2)User Profile Service Application, Managed Metadata Service, and
    Search Service Application are running for particular web application
    3)Self-Service site creation is enabled for web application
    4)In permission policy ,add permission policy level and grant permission to create subsites
    5)In user policy add everyone for all zones and choose permission policy create in step 4
    6)Check if User profile service and user profile synchronization service is running,and users are synchronized
    I guess the issue is due to user profile synchronization as mysite generally appears for admin account who don not require synchronization.
    check the following link to verify your configuration
    https://www.nothingbutsharepoint.com/sites/itpro/pages/sharepoint-2013-creating-and-configuring-mysite.aspx
    Please Mark it as answer if this reply helps you in resolving the issue,It will help other users facing similar problem

Maybe you are looking for

  • My Mail emails no longer show up once I click to highlight.

    I used to be able to click once on an email and then see the body of the email that fits in the window.  That no longer works.  Now I have to double click and open the entire email to get any view of it.  Thought it might have been some format change

  • How does a record type and table type works

    Hi, How a record type and table type work for the ref cursor, below i m giving an example but its giving me errors can any one help me for this? declare type empcurtyp is ref cursor; type rectype is record (veid t.emp_id%type, vename t.ename%type); T

  • Problems accessing 1 remote desktop when connected with VPN

    Hi everyone, I have an ASA 5505 and have a problem where when I connect through VPN I can RDP into a server using its internal address but I cannot RDP to another server using its internal address. The one I can connect to has an IP of 192.168.2.10 a

  • Alternative to Print preview in Script

    Hi all,   i can not see the print preview for my form. its showing <i>'No authorization for output device LP01'</i>. <b>Is there any alternative to display the print priview</b>.using the OPEN_FORM Function module

  • Hierachical Tree in developer2k

    Hi, I want to create a hierarchical tree, but unable to do that. I tried do that with the help of forms help but there is some mistakes and its showing err frm-47321 "Data used to populate tree is invalid". Can any one help me in this regard?? Regard