06-27-2006 06:18 PM - edited 03-09-2019 03:25 PM
My Logs are flooded with this message:
Jun 27 2006 11:54:40|106001: Inbound TCP connection denied from 192.168.11.15/4670 to 192.168.11.138/3500 flags SYN on interface Inside
I dont understand why this happening, especially when both machines are on the inside interface. Here is my config if it helps.
06-27-2006 08:43 PM
Hi
As per CCO its just a connection notification message no action required.
do refer this link for more info..
regds
06-27-2006 11:34 PM
ASA is dropping those packets because source and destination are on the same interface. PIX will never send icmp redirect (as a router could) and will only allow this traffic if it is v7.2 and you have "same-security-traffic permit intra-interface", and even then it must see both halves of the connection.
Your best bet is to find out why this is getting sent to the ASA and change it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide