errors in web access

Answered Question
Aug 27th, 2010

One of our European location is encountering below 2 errors on their firewall.

Expected SYN, got FIN-ACK & Expected  SYN, got RST

this firewall is non-cisco product. these are seen more in lines where internet users try using organisation web

server inside their secure zone segment. no problems have been reported out of these, but it is seen very frequently.

Any help will be highly appreciated,

Thanks.

I have this problem too.
0 votes
Correct Answer by Kureli Sankar about 6 years 4 months ago

I applaude your confidence in Cisco products and engineers.

I googled this "expected syn got fin ack" and found this link

http://mail.adeptech.com/pipermail/sidewinder/2008-July/002631.html

which pretty much says to read the error message as

Expected SYN-ACK, got FIN-ACK &

Expected  SYN-ACK, got RST

Meaning the second packet of the 3-way hand shake does not arrive.

Pls. collect wireshark (http://www.wireshark.org) captures and find out who is sending the reset or the fin-ack.

-KS

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Kureli Sankar Mon, 08/30/2010 - 20:52

I applaude your confidence in Cisco products and engineers.

I googled this "expected syn got fin ack" and found this link

http://mail.adeptech.com/pipermail/sidewinder/2008-July/002631.html

which pretty much says to read the error message as

Expected SYN-ACK, got FIN-ACK &

Expected  SYN-ACK, got RST

Meaning the second packet of the 3-way hand shake does not arrive.

Pls. collect wireshark (http://www.wireshark.org) captures and find out who is sending the reset or the fin-ack.

-KS

Actions

This Discussion