Preview Tool

Cisco Bug: CSCuj54639 - ASA drops inspected HTTP when unrelated service-policy is removed

Last Modified

Nov 27, 2020

Products (1)

  • Cisco Adaptive Security Appliance (ASA) Software

Known Affected Releases


Description (partial)

If 2 different interfaces use 2 different policy-maps that each reference the same L7 HTTP inspection policy-map, all HTTP traffic through the first interface will fail if the policy-map used by the 2nd interface is removed. For example:

ciscoasa# sh nameif
Interface                Name                     Security
GigabitEthernet0/1       outside                    0
GigabitEthernet0/2       inside                   100
GigabitEthernet0/3       dmz                        0

policy-map type inspect http l7-http-pm
 match request method trace
  reset log
policy-map dmz-policy
 class inspection_default
  inspect http l7-http-pm
policy-map global_policy
 class inspection_default
  inspect http l7-http-pm
service-policy global_policy global
service-policy dmz-policy interface dmz

If 'service-policy dmz-policy interface dmz' is removed, all HTTP traffic on the inside interface will fail with the following logs:

%ASA-6-302013: Built outbound TCP connection 72 for outside: ( to inside: (
%ASA-4-507003: tcp flow from inside: to outside: terminated by inspection engine, reason - reset unconditionally.
%ASA-6-302014: Teardown TCP connection 72 for outside: to inside: duration 0:00:00 bytes 0 Flow closed by inspection

This issue only occurs when the same L7 policy-map (policy-map type inspect http) is shared amongst multiple interfaces.
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.