"syn NOT rcvd" tells you that the machine on which nrconns was run, has sent a SYN packet to initiate the connection, but has not received a corresponding SYN packet from the machine it is trying to comunicate with.
As root on the sensor execute:
snoop -d iprb0 udp
example:
snoop -d iprb0 10.1.1.1 20.2.2.2 udp
NOTE: If using the 4210 sensor replace iprb0 with iprb1
You should see UDP packets from port 45000 on the sensor going to port 45000 on the director.
Now use the Add Host on nrConfigure to add the sensor.
You should now start seeing UDP packets from port 45000 on the director going to port 45000 on the sensor.
If you do not see the packets coming from the sensor then the services on the sensor are not started, or the ip addresses are incorrect in your command or configuration.
If you do not see the packets coming from the director then the services on the director are not started, or the ip addresses are incorrect in your command or configuration, or the PIX Firewalls have not been properly configured to allow UDP port 45000 traffic through the VPN Tunnel.
If you see the UDP packets from the director, but they are fragmented, then your VPN tunnel is fragmenting the UDP packets and this could cause problems with the postoffice communication.
NOTE: If using NAT then be sure that the proper addresses are being used when runnning sysconfig-sensor and the Add Host wizard in nrConfigure.