Inside Network access DMZ Host

Unanswered Question
Jun 23rd, 2008
User Badges:


I Have a ASA 5510 on my network, which 3 networks (inside, outside, dmz).

When a dmz host access a inside Host, works ok, but when a inside host try access the dmz host, the following message is displayed on LOG:

Deny TCP (no connection) from hid-dmz/25 to hid-iwss/44674 flags SYN ACK on interface dmz

The static nat:

static (dmz,inside) netmask

static (inside,dmz) netmask

where: DMZ Network Inside Network

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
acomiskey Mon, 06/23/2008 - 10:40
User Badges:
  • Green, 3000 points or more

You shouldn't need this...

no static (dmz,inside) netmask

gilbertojardim Mon, 06/23/2008 - 10:52
User Badges:

even removing this, the problem continues...

all acl's is set to permit traffic...

mohammed_moustafa Tue, 06/24/2008 - 02:02
User Badges:

Hi Dear,

I doubt much that the problem is tha nat translation, error message says no connection this means the TCP SYNC and SYNC/ACK reply are going different pathes so firewall will drop that reply. but to make sure the problem is not in the nat translation use this command:

no nat-control

and remove both the static nat commands

If you can post the configuration of your firewall it will be very helpful.

let me know the results.


gilbertojardim Tue, 06/24/2008 - 04:12
User Badges:

if i'm remove static nat, the log display "no translation"... With "no nat-control", the problem continues...

Follow the config in attachment...



This Discussion