Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

nb3
New Member

ASA-Checkpoint L2L VPN traffic dropped (SYN flag)

Having trouble with a L2L VPN between a ASA5520 and Checkpoint NGX. Traffic passes through just fine for most users but we are seeing problems where some users (but not always the same users) are unable to connect. I'm seeing

Inbound TCP connection denied from x.x.x.x/1171 to y.y.y.y/80 flags SYN on interface Outside.

My understanding of this is the ASA is seeing a new connection coming in (SYN flag is set) but the ASA thinks there is an existing connection it should be using.

Any ideas on what would cause this and if there is anyway to clear the connection for a single IP address?

  • VPN
1 REPLY
nb3
New Member

Re: ASA-Checkpoint L2L VPN traffic dropped (SYN flag)

FYI. This was caused by bug CSCsg60095. Upgrading to 7.2(3) resolved the problem.

137
Views
0
Helpful
1
Replies