cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5894
Views
0
Helpful
4
Replies

TCP connection Errors and Pix TCP flags..

peter-net
Level 1
Level 1

A remote client tried legitmately to 3 way handshake a TCP connection through our firwall and instead of going into UP state, the TCP connection failed, with the Pix "Show conn" flags showing "SaA" on the client side and "SaAB" flags on the server side. We think we can decode these flags - but we cant figure out the causation. No devices went down or failed-over to my knowledge, and there appears to have been no other reported events occuring that could have caused or impacted this situation. Any ideas anyone as to what may have caused the TCP connection attempt to have failed? It seemed to right itself also after a while - we did nothing...but I need some answers for the suits when it happens again - thanks peter@it-123.co.uk

4 Replies 4

abinjola
Cisco Employee
Cisco Employee

SaAB-->initiat sym from outside, and firewall waiting for synack, there was no returns reply sent to firewall,the default gateway got missing, check for routing issues...is the client/server having dual NICs

not aware of any routing probs, but could the tcp connection have just timed out server side (due to a slow server respnse issue) and this left the connection incomplete?

well Pix/ASA terminates half open connections after certain time,

This is an embryonic connection where the server did not reply back with SYNACK, either the server was down/or return route was missin, that you need to fix on your server side

IS it possible to modify the firewall to allow for the time delay and thus allow the connection to succeed if it is a latencty problem from the app?

Review Cisco Networking products for a $25 gift card