cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
767
Views
0
Helpful
2
Replies

ASA Syslog Event 106001

jason.scott
Level 1
Level 1

I'm seeing a lot of events in our ASA logs for 106001 relating to external source TCP (port 80) connections being denied inbound to our PAT address. The sources are all valid web sites which users are accessing. If a source inside connects to a website outside, surely the return traffic will be permitted without needing any extra ACLs?

2 Replies 2

didyap
Level 6
Level 6

This is a connection-related message. This message occurs when an attempt to connect to an inside address is denied by your security policy. Possible tcp_flags values correspond to the flags in the TCP header that were present when the connection was denied. Indeed that means the conn table removed the connection. Such kind of messages are usually generated due to bad server kernel implementation.

So the websites generating these messages are at fault rather than anything wrong with our configuration or something malicious?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: