cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
562
Views
0
Helpful
4
Replies

deny TCP (no connection)

rsullivan1
Level 1
Level 1

I see a lot of these messages, maybe hundreds per minutes. I feel this is not normal, but can never find any convincing information either way. Can anyone elaborate?

4 Replies 4

eddie.mitchell
Level 3
Level 3

Can you tell us what message ID is associated with what you're seeing?

http://www.cisco.com/en/US/docs/security/pix/pix63/system/message/pixemsgs.html

Is this firewall on your network perimeter? Are all of these messages being generated from the same source IP address? Same destination IP? Same source or destination port?

This is our perimeter which then interfaces another LAN. Another firewall is used at the internet perimeter. The addresses are not the same, although you see a cluster of denies (between 2 and 6 for each deny). We had an explicit deny any any log entry at the end of the outside rules. I just disabled this and noticed a significant drop in the logged traffic. I'm not sure this is just a band-aid to the real issue though.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card