Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

SYN ACK missing related with a firewall inside a DMZ of another ASA

Hi I have two control point, two firewall

the second one is linked inside one DMZ from the first firewall

route is good and inside the DMZ from first firewall I have servers too

so to be more clear we could call as IP for the DMZ from first firewall, Interface IP 1.1.1.1 that generate this DMZ with first firewall (netmask 255.255.0.0)

inside the DMZ I have an interface from second firewall with IP 1.1.1.5 and inside DMZ 1.1/16 I have servers too

keep one test server with IP 1.1.1.3

The LAN passing the second firewall is 2.2.2.1 ever 16 bits of netmask (255.255.0.0)

inside the DMZ generated from second firewall I have a machine with IP 2.2.2.9 that need to access in TCP services on machine 1.1.1.3

running the test I have this scenario:

TCP packets from 2.2.2.9 pass the second firewall and arrive inside DMZ with net 1.1/16 and arrive to server with IP 1.1.1.3

defaul gateway (to answer to originating machine with IP 2.2.2.9) is 1.1.1.1

ASA interface 1.1.1.1 claim a missing related as it haven't mapped the connection that has passed on first firewall. I need only that 1.1.1.1 route packets to second firewall (who own net 2.2/16) avoiding to be trappen in missing related check

at start it was working! around 1 year ago we upgraded IOS to 8.4 and ever so late (one year) doing maintenance to a machine I discovered it was no longer talking with these server on net 1.1/16

I have found on cisco docs chapter 51 and TCP State Bypass         ............            is this the only answer and the right answer?

before was working, is something that has changed inside ASA IOS 8.4 ?

HTML version of TCP State Bypass I found that should, could solve my issue is:

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b2d922.shtml

Any other info or solutions? is that what I have to configure so to solve? and before was working why no more?

thanks

edi9t

  • Firewalling
1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

SYN ACK missing related with a firewall inside a DMZ of another

Alberto,

Wanna switch to spanish? Do you have the configuration when it was running pre-8.3 NAT configuration? The scenario is not very clear,  maybe a quick diagram could help.

Mike

Mike
3 REPLIES
Cisco Employee

SYN ACK missing related with a firewall inside a DMZ of another

Alberto,

Wanna switch to spanish? Do you have the configuration when it was running pre-8.3 NAT configuration? The scenario is not very clear,  maybe a quick diagram could help.

Mike

Mike
New Member

SYN ACK missing related with a firewall inside a DMZ of another

New Member

SYN ACK missing related with a firewall inside a DMZ of another

errouneosly I clicked as answered

411
Views
0
Helpful
3
Replies
This widget could not be displayed.