<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cisco ASA on Netdata</title><link>https://www.netdata.cloud/tags/cisco-asa/</link><description>Recent content in Cisco ASA on Netdata</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://www.netdata.cloud/tags/cisco-asa/index.xml" rel="self" type="application/rss+xml"/><item><title>License expiry silently disabling features: monitor days-to-expiry</title><link>https://www.netdata.cloud/guides/network/network-license-expiry-silent-disable/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.netdata.cloud/guides/network/network-license-expiry-silent-disable/</guid><description>&lt;p&gt;Your firewall dashboard shows green. Interfaces are up, CPU and memory are normal, traffic is flowing. But at 09:00, someone reports VPN connections failing, IPS no longer blocking threats, or URL filtering not enforcing policy. A feature license expired at midnight, and the device silently stopped performing the licensed function without raising a visible alarm.&lt;/p&gt;&#10;&lt;p&gt;The device stays up, counters keep incrementing, throughput looks normal. The license-expiry message in syslog is low severity and gets buried under routine noise. By the time someone notices, the feature has been disabled for hours.&lt;/p&gt;</description></item><item><title>NAT and session-table exhaustion: catching it before connections fail</title><link>https://www.netdata.cloud/guides/network/network-nat-session-table-exhaustion/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.netdata.cloud/guides/network/network-nat-session-table-exhaustion/</guid><description>&lt;p&gt;New connections fail while existing ones keep working. Applications report &amp;ldquo;connection refused&amp;rdquo; or timeouts. Open SSH sessions stay alive, but new SSH attempts hang. Your monitoring shows the firewall or NAT gateway is up, interfaces are healthy, and CPU is normal. The session or NAT translation table is full.&lt;/p&gt;&#10;&lt;p&gt;Session-table exhaustion is a cliff-edge failure. The table degrades gracefully until it hits its limit, then every new connection is denied. Existing flows continue because their entries are already in the table. The symptom pattern is distinctive but easy to misdiagnose as application failure, DNS issues, or upstream provider problems, because the applications are the ones reporting errors.&lt;/p&gt;</description></item></channel></rss>