<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco &#8211; ASA Error message %ASA-7-710005: TCP request discarded</title>
	<atom:link href="http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/</link>
	<description>Tips and Video Tutorials - Cisco .:. Linux .:. VOIP</description>
	<lastBuildDate>Tue, 29 Nov 2011 04:01:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Chris</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-37805</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 11 Feb 2011 22:06:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-37805</guid>
		<description>Thanks for the post! Helped us out!</description>
		<content:encoded><![CDATA[<p>Thanks for the post! Helped us out!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bennie Rayno</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-37785</link>
		<dc:creator>Bennie Rayno</dc:creator>
		<pubDate>Thu, 10 Feb 2011 03:50:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-37785</guid>
		<description>Thanks for sharing superb informations. Your web site is so cool. I am impressed by the details that you have on this site. It reveals how nicely you understand  this subject. Bookmarked this website page, will come back for extra articles. You, my pal, ROCK! I found simply the info I already searched everywhere and just could not come across. </description>
		<content:encoded><![CDATA[<p>Thanks for sharing superb informations. Your web site is so cool. I am impressed by the details that you have on this site. It reveals how nicely you understand  this subject. Bookmarked this website page, will come back for extra articles. You, my pal, ROCK! I found simply the info I already searched everywhere and just could not come across.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Izoj</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-37619</link>
		<dc:creator>Izoj</dc:creator>
		<pubDate>Tue, 25 Jan 2011 11:01:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-37619</guid>
		<description>Tell me about it!!!
I have been trying to deploy this &quot;smart&quot; ASA 5505 on a part time basis - 3 weeks. Its not working well yet.

My set up is as follows:
ISP  CiscoRTR(1700 or 800)ASA5505LAN

Internal clients can now browse and send mail; but incoming mails are blocked.

After capture of SMTP, I found that mss is larger than 512bytes DNSSec message-length.

Tried to change and this is what the ASDM 5.x is doing:

policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
  message-length maximum client auto

Incoming mails are still blocked, I understand the device is still using 512 in preference to client auto.

Anyone with a hint to find a work around.

Rgds</description>
		<content:encoded><![CDATA[<p>Tell me about it!!!<br />
I have been trying to deploy this &#8220;smart&#8221; ASA 5505 on a part time basis &#8211; 3 weeks. Its not working well yet.</p>
<p>My set up is as follows:<br />
ISP  CiscoRTR(1700 or 800)ASA5505LAN</p>
<p>Internal clients can now browse and send mail; but incoming mails are blocked.</p>
<p>After capture of SMTP, I found that mss is larger than 512bytes DNSSec message-length.</p>
<p>Tried to change and this is what the ASDM 5.x is doing:</p>
<p>policy-map type inspect dns preset_dns_map<br />
 parameters<br />
  message-length maximum 512<br />
  message-length maximum client auto</p>
<p>Incoming mails are still blocked, I understand the device is still using 512 in preference to client auto.</p>
<p>Anyone with a hint to find a work around.</p>
<p>Rgds</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-35038</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Wed, 01 Dec 2010 19:15:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-35038</guid>
		<description>DOFF! We were just talking about you yesterday (Spirk&#039;s going away lunch). 

Good to see you on the site. Thanks for all the helpful tips.</description>
		<content:encoded><![CDATA[<p>DOFF! We were just talking about you yesterday (Spirk&#8217;s going away lunch). </p>
<p>Good to see you on the site. Thanks for all the helpful tips.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doff</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-35024</link>
		<dc:creator>Doff</dc:creator>
		<pubDate>Fri, 26 Nov 2010 18:54:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-35024</guid>
		<description>Crazy that I ran into BlindHog after all these years!

Also, keep an eye out for any DNS issues related to DNSsec and EDNSO. If the FW (specifically a pix or ASA) is configured, by default, for DNS packet inspection, which is set at 512b any DNS packets larger than the default configured size will be dropped. DNSSec will always be larger than 512b. Starting in 8.2.2 of Cisco ASA software ver, it is possible to configure the setting as auto in the DNS Inspection size. 

ASA configuration:
 policy-map type inspect dns preset_dns_map
  parameters
   message-length maximum maximum client auto

On the ASA, you can issue the &#039;sh asp drop frame&#039; to view the stats of any DNS related drops. 
internetfw# sh asp drop frame
  DNS Inspect invalid packet (inspect-dns-invalid-pak)                       603
  DNS Inspect invalid domain label (inspect-dns-invalid-domain-label)      17513
  DNS Inspect packet too long (inspect-dns-pak-too-long)                    2101
  DNS Inspect id not matched (inspect-dns-id-not-matched)                  57638


Comcast has a link to a testing site to see if your firewall handles the DNSsec properly. 
http://www.dnssec-failed.org/

http://www.dnssec.comcast.net/</description>
		<content:encoded><![CDATA[<p>Crazy that I ran into BlindHog after all these years!</p>
<p>Also, keep an eye out for any DNS issues related to DNSsec and EDNSO. If the FW (specifically a pix or ASA) is configured, by default, for DNS packet inspection, which is set at 512b any DNS packets larger than the default configured size will be dropped. DNSSec will always be larger than 512b. Starting in 8.2.2 of Cisco ASA software ver, it is possible to configure the setting as auto in the DNS Inspection size. </p>
<p>ASA configuration:<br />
 policy-map type inspect dns preset_dns_map<br />
  parameters<br />
   message-length maximum maximum client auto</p>
<p>On the ASA, you can issue the &#8216;sh asp drop frame&#8217; to view the stats of any DNS related drops.<br />
internetfw# sh asp drop frame<br />
  DNS Inspect invalid packet (inspect-dns-invalid-pak)                       603<br />
  DNS Inspect invalid domain label (inspect-dns-invalid-domain-label)      17513<br />
  DNS Inspect packet too long (inspect-dns-pak-too-long)                    2101<br />
  DNS Inspect id not matched (inspect-dns-id-not-matched)                  57638</p>
<p>Comcast has a link to a testing site to see if your firewall handles the DNSsec properly.<br />
<a href="http://www.dnssec-failed.org/" rel="nofollow">http://www.dnssec-failed.org/</a></p>
<p><a href="http://www.dnssec.comcast.net/" rel="nofollow">http://www.dnssec.comcast.net/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Julie</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-32807</link>
		<dc:creator>Julie</dc:creator>
		<pubDate>Tue, 03 Nov 2009 02:30:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-32807</guid>
		<description>Hi Josh,

I just wanted to say thanks for this post.  It has saved me from tearing my hair out.  I also want to let everyone know, I ran into this problem with a PIX 515 running 8.0 and 7.2(4).  So just keep in mind, this is not just an ASA issue.

Thanks again!</description>
		<content:encoded><![CDATA[<p>Hi Josh,</p>
<p>I just wanted to say thanks for this post.  It has saved me from tearing my hair out.  I also want to let everyone know, I ran into this problem with a PIX 515 running 8.0 and 7.2(4).  So just keep in mind, this is not just an ASA issue.</p>
<p>Thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: greg</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-32559</link>
		<dc:creator>greg</dc:creator>
		<pubDate>Thu, 13 Aug 2009 17:09:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-32559</guid>
		<description>I have the same problem. After I configured my new ASA 5505 with multiple PAT address I was not able to see any traffic passing the appliance in and out. I was able to ping both the inside and outside interface including through my security router to my border router and was not able to show any traffic counts with my access list. Why wasn&#039;t there any warning from cisco about this? The only sure thing I got from there tutorial was, as long as you have configured a default route in your appliance i.e. route outside  0.0.0.0 0.0.0.0 &quot;gateway&quot; 1 , you should be able to pass all your traffic in and out the appliance,but this was not the case. Is there any one out there has any solution for multiple PAT thorugh the ASA?</description>
		<content:encoded><![CDATA[<p>I have the same problem. After I configured my new ASA 5505 with multiple PAT address I was not able to see any traffic passing the appliance in and out. I was able to ping both the inside and outside interface including through my security router to my border router and was not able to show any traffic counts with my access list. Why wasn&#8217;t there any warning from cisco about this? The only sure thing I got from there tutorial was, as long as you have configured a default route in your appliance i.e. route outside  0.0.0.0 0.0.0.0 &#8220;gateway&#8221; 1 , you should be able to pass all your traffic in and out the appliance,but this was not the case. Is there any one out there has any solution for multiple PAT thorugh the ASA?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-24008</link>
		<dc:creator>Anton</dc:creator>
		<pubDate>Sun, 25 Jan 2009 20:40:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-24008</guid>
		<description>Thanks, Josh!</description>
		<content:encoded><![CDATA[<p>Thanks, Josh!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-11264</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Thu, 15 May 2008 16:15:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-11264</guid>
		<description>I have a similar problem with dhcp replies back to an ASA (7.2(2)) being dropped. Any ideas?

%ASA-6-302015: Built outbound UDP connection 458 for inside:141.1.255.8/67 (141.1.255.8/67) to NP Identity Ifc:141.1.255.12/68 (141.1.255.12/68)
%ASA-7-710005: UDP request discarded from 141.1.255.8/67 to inside:255.255.255.255/67
%ASA-7-710005: UDP request discarded from 141.1.255.8/67 to inside:255.255.255.255/67</description>
		<content:encoded><![CDATA[<p>I have a similar problem with dhcp replies back to an ASA (7.2(2)) being dropped. Any ideas?</p>
<p>%ASA-6-302015: Built outbound UDP connection 458 for inside:141.1.255.8/67 (141.1.255.8/67) to NP Identity Ifc:141.1.255.12/68 (141.1.255.12/68)<br />
%ASA-7-710005: UDP request discarded from 141.1.255.8/67 to inside:255.255.255.255/67<br />
%ASA-7-710005: UDP request discarded from 141.1.255.8/67 to inside:255.255.255.255/67</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bky</title>
		<link>http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/comment-page-1/#comment-7451</link>
		<dc:creator>bky</dc:creator>
		<pubDate>Wed, 09 Jan 2008 22:51:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-asa-error-message-asa-7-710005-tcp-request-discarded/#comment-7451</guid>
		<description>TheGrave, that is why cisco certs earn you the big bucks ;)</description>
		<content:encoded><![CDATA[<p>TheGrave, that is why cisco certs earn you the big bucks <img src='http://www.blindhog.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

