Guest

Preview Tool

Cisco Bug: CSCuo19916 - ASA - Cut Through Proxy sends empty redirect w/ Virtual HTTP and Telnet

Last Modified

Apr 16, 2020

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

8.4(7) 9.1(2)

Description (partial)

Symptom:
When using cut-through-proxy, virtual http, and virtual telnet on an ASA, clients may receive 302 
Moved responses for the redirect that contain no location.  With some browsers (confirmed on 
IE9), this behavior causes the client to continuously reset and restart the connection which results 
in a DOS situation for the ASA and any associated syslogs servers due to thousands of 
connection builds/teardowns within very short period of time.

Conditions:
1.  Must be using cut-through-proxy on the ASA
2.  Must have a virtual HTTP configured as the redirect destination IP in the authentication proxy 
ACL
3.  Must also have virtual telnet configured on the ASA with the same IP as virtual HTTP
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.