Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

Inbound TCP connection denied from x to y

Hi Everyone,

Seeing following logs on ASA:

  Inbound TCP connection denied from x to y flags SYN ACK on interface Net
  Inbound TCP connection denied from x to y flags ACK on interface Net

Does this mean that there is Asymmetric route or missing ACL?

Regards

MAhesh

1 ACCEPTED SOLUTION

Accepted Solutions

Inbound TCP connection denied from x to y

Hello Maheshm

First option Asymmetric routing, use the TCP state-bypass option as a workaround.

Remove the asymetric routing as the real fix

Check my blog at http:laguiadelnetworking.com for further information.

Cheers,

Julio Carvajal Segura

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
3 REPLIES

Inbound TCP connection denied from x to y

Hello Maheshm

First option Asymmetric routing, use the TCP state-bypass option as a workaround.

Remove the asymetric routing as the real fix

Check my blog at http:laguiadelnetworking.com for further information.

Cheers,

Julio Carvajal Segura

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
New Member

Inbound TCP connection denied from x to y

Hi Julio,

I tested my applying ACL   so you are correct its Asymmetric routing.

Regards

MAhesh

Inbound TCP connection denied from x to y

Hello Mahesh,

Thanks for the head´s up.

Check my blog at http:laguiadelnetworking.com for further information.

Cheers,

Julio Carvajal Segura

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
289
Views
0
Helpful
3
Replies
CreatePlease to create content