Guest

Preview Tool

Cisco Bug: CSCvu24703 - ENH: FTD - Flow-Offload should be able to coexist with Rate-limiting Feature (QoS)

Last Modified

Sep 02, 2020

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

9.14(1)

Description (partial)

Symptom:
When flow-offload is enabled with QoS rate-limiting is not enforced. The initial part of the connection is rate-limited but as soon as the connection is offloaded, Lina is unable to enforce rate-limit.

Offload flag - o

FTD01# sh conn  flow-rule qos 268442629
445 in use, 1109 most used
Inspect Snort:
	preserve-connection: 150 enabled, 22 in effect, 748 most enabled, 58 most in effect

TCP Inside  1.3.1.2:60716 Outside  92.122.164.90:443, idle 0:00:00, bytes 149811, flags UxIOoN1

Conditions:
Flow-offload configured with QoS rate-limiting
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.