Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

duplicate tcp syn messages

'm using the ASA for anyconnect users and I keep seeing log messages similar to the following:

4 date=Oct 07 2009 Source IP= Source Port=17571 Destination IP= Destination Port53887 Duplicate TCP SYN from inside: to inside: with different initial sequence number

The source changes from various server (so far our Anti-virus server, dns, and Active directory servers) the destination appears to be client ip's that have disconnected.

I would like to stop this as it is filling my logs up with spurious information

Cisco Employee

Re: duplicate tcp syn messages

Do you have another firewall in the middle that may be randomizing sequence numbers?

New Member

Re: duplicate tcp syn messages

I do have a firewall services module between them, how do I tell if it is randomizing the sequence numbers?

Cisco Employee

Re: duplicate tcp syn messages

It does it by default unless you disable it, through a tcp map.

CreatePlease login to create content