cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
520
Views
0
Helpful
4
Replies

Connection lan2lan failed

dflores83
Level 1
Level 1

Hi guys,

I have a problem when try to connect two LAN (one ASA on each LAN)

I have this error----%PIX|ASA-6-106015: Deny TCP (no connection) from IP_address/port to

IP_address/port flags tcp_flags on interface interface_name.

Explanation The security appliance discarded a TCP packet that has no associated connection in the security appliance connection table. The security appliance looks for a SYN flag in the packet, which indicates a request to establish a new connection. If the SYN flag is not set, and there is not an existing connection, the security appliance discards the packet.Recommended Action None required unless the security appliance receives a large volume of these invalid TCP packets. If this is the case, trace the packets to the source and determine the reason these packets were sent. ----

I try to apply the comand acess-list nonat, and same-security-traffic permit inter-interface; same-security-traffic permit intra-interface; but nothing happend

Somebody have any idea......

thanks

4 Replies 4

John Blakley
VIP Alumni
VIP Alumni

Can you post a config?

HTH, John *** Please rate all useful posts ***

here the config,

In this case, the ASA only can do ICMP, but not TCP, (ex...the HQ can ping to branch 1 and branch 2.)

The description said:

Deny TCP (no connection) from x.x.x.x/1728 to x.x.x.x/443 flags RST on Interface Inside

and the explanation:

The security appliance discarded a TCP packet that has no associated connection in the security appliance connection table

where is your complete nat exempt access list in config, this is not complete config, post config including acls pertaining to L2L tunnel..

that message simply saids tcp denied from a source that it is probably not part of your l2l tunnel policy.

what network or source from other side of tunnel is trying to access what destination on your inside interface, you need to add remote LAN/source in your l2l interesting traffic nat exempt policy and crypto acl.

regards

Jorge Rodriguez

Hi,

thanks

I was doing your recomendations but, the problem is the same.......this is the new config

some recommendation?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card