Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

asa5505v8 tcp syn denied on inside

"Inbound TCP connection denied from 1.4.19.244/1635 to 1.4.20.212/4001 flags SYN on interface inside"

The vlan on the inside interface (vlan19) also needs access to systems on vlan20 so we have a static route on the asa that points to a router that also sits on vlan19. I can ping the two vlans from the asa's inside interface but I'm not sure why the above error occurs or how to stop it.

1 REPLY
Hall of Fame Super Blue

Re: asa5505v8 tcp syn denied on inside

Keith

So is the default-gateway for clients on vlan 19 the ASA inside interface ?.

If so have you added this to your config -

asa(config)# same-security-traffic permit intra-interface

if you don't have that in your config traffic will not be allowed back out the same interface it arrived on to get to it's destination.

Jon

148
Views
0
Helpful
1
Replies