<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISCO ASA 5512  - TCP Syn Timeout in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720861#M1049786</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, this wont work for across the interface if you want to source from ASA interface or ping to the ASA interface when not connected to the interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;AJ&lt;/P&gt;</description>
    <pubDate>Mon, 08 Oct 2018 08:57:48 GMT</pubDate>
    <dc:creator>Ajay Saini</dc:creator>
    <dc:date>2018-10-08T08:57:48Z</dc:date>
    <item>
      <title>CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3719555#M1049709</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source is getting SYN,ACK from destination but rather than sending final SYN it sends Host Unreaachable.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Capture attached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:19:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3719555#M1049709</guid>
      <dc:creator>jsishodia</dc:creator>
      <dc:date>2020-02-21T16:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3719583#M1049733</link>
      <description>&lt;P&gt;Can you post the configuration to review.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 21:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3719583#M1049733</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-04T21:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720547#M1049746</link>
      <description>&lt;P style="text-align: left;"&gt;Hello,&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;Where were these captures taken? These host unreachable icmp error indicates that the end host is not either reachable through some router in between the path (could be a firewall) or the host does not have a default gateway configured. In your case, the syn packet goes out fine. We need to identify where these captures were taken and find out if Unreachable was sent out by the host itself or some layer 3 device in between.&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&lt;A href="https://www.savvius.com/networking-glossary/tcp_ip_overview/icmp/unreachable/" target="_blank"&gt;https://www.savvius.com/networking-glossary/tcp_ip_overview/icmp/unreachable/&lt;/A&gt;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;HTH&lt;BR /&gt;AJ&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2018 07:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720547#M1049746</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-10-07T07:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720572#M1049754</link>
      <description>&lt;P&gt;Hi Ajay&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Topology is like&amp;nbsp; ASA 1 -&amp;gt; ASA 2 - &amp;gt; Host&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am doing a TCP ping from ASA 1 outside interface to Host , the capture is of inside interface ASA 1&lt;/P&gt;
&lt;P&gt;ASA 1 is translatign the IPs are per NAT rule properly. as it should.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The comm is like&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA sends SYN&lt;/P&gt;
&lt;P&gt;Host Sends SYN,ACK&lt;/P&gt;
&lt;P&gt;Then the 3rd packet is sent of unreachable to host ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So issue is on ASA 1 I think...becuase host is responding I have taken capture on ASA 1 &amp;amp; 2 both ...host sends SYN, ACK&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but from ASA 1 sends unreachable in place SYN ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached is the caputre of outside interface..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2018 10:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720572#M1049754</guid>
      <dc:creator>jsishodia</dc:creator>
      <dc:date>2018-10-07T10:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720576#M1049766</link>
      <description>&lt;P&gt;So, you are doing a tcp based ping from ASA1 , is that correct? or the ping is from a host behind the ASA1?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you provide the command that you are issuing on the ASA1 or the host to run this ping.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2018 10:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720576#M1049766</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-10-07T10:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720638#M1049777</link>
      <description>&lt;P&gt;Hi Ajay&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, That is correct.&lt;/P&gt;
&lt;P&gt;I am doign TCP based ping from ASA 1 and am doing it from ASDM&amp;nbsp; -&amp;gt;Tools-&amp;gt; Ping&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By giving source interface and IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2018 17:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720638#M1049777</guid>
      <dc:creator>jsishodia</dc:creator>
      <dc:date>2018-10-07T17:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720795#M1049779</link>
      <description>&lt;P&gt;Ah, if you are trying to ping outside ip addresses sourced from inside interface of ASA, it will never work. Thats ASA design, you should source the interface of ASA which has the route towards the destination to be pinged.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;AJ&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 06:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720795#M1049779</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-10-08T06:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720854#M1049781</link>
      <description>&lt;P&gt;Hi Ajay&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is what am doing from&amp;nbsp; OUTSIDE to INSIDE&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 08:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720854#M1049781</guid>
      <dc:creator>jsishodia</dc:creator>
      <dc:date>2018-10-08T08:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720861#M1049786</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, this wont work for across the interface if you want to source from ASA interface or ping to the ASA interface when not connected to the interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;AJ&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 08:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720861#M1049786</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-10-08T08:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720871#M1049789</link>
      <description>&lt;P&gt;hi Ajay&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Outside interface is connected to MPLS network where actual source resides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So inspite of asking the actual source to try again and again am trying to investigate this issue by creating a TCP connection from ASA itself by taking outside interface as source using the source IP ... which woks fine till SYN,ACK but it sends 3rd packet as unreachable ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 09:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3720871#M1049789</guid>
      <dc:creator>jsishodia</dc:creator>
      <dc:date>2018-10-08T09:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA 5512  - TCP Syn Timeout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3721542#M1049793</link>
      <description>&lt;P&gt;Since ASA does not own that ip address, thats a valid reason why it should be sending the host unreachable error message.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideally, in a router scenario, you would have created a loopback interface and tested, but ASA won't be as friendly as you want it to be. I would suggest looking for alternatives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;AJ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 05:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5512-tcp-syn-timeout/m-p/3721542#M1049793</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-10-09T05:44:00Z</dc:date>
    </item>
  </channel>
</rss>

