<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX Syslog Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-syslog-question/m-p/334894#M1059622</link>
    <description>&lt;P&gt;I just set up a syslog server for my PIX and am trying to figure out why I am getting so many messages.  I am gettings tons of these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX-2-106001: Inbound TCP connection denied from [internet web server]:80 [PIX Outside Global Interface]:[Random PAT port] TCP_flags&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully that syntax made sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically the PIX is denying traffic from internet servers on port 80 with the destination to the global interface.  The destination port is always different, usually incrementing on the higher numbers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As best as I can tell an inside host is hitting an external web page, going through PAT on the firewall, and the firewall is denying the return traffic.  The weird thing is that my users are not complaining of problems with the internet.  So why am I getting tons of these severity 2 syslog messages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I explained that properly.  Thanks for the help.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:46:45 GMT</pubDate>
    <dc:creator>davemit</dc:creator>
    <dc:date>2020-02-21T07:46:45Z</dc:date>
    <item>
      <title>PIX Syslog Question</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-question/m-p/334894#M1059622</link>
      <description>&lt;P&gt;I just set up a syslog server for my PIX and am trying to figure out why I am getting so many messages.  I am gettings tons of these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX-2-106001: Inbound TCP connection denied from [internet web server]:80 [PIX Outside Global Interface]:[Random PAT port] TCP_flags&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully that syntax made sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically the PIX is denying traffic from internet servers on port 80 with the destination to the global interface.  The destination port is always different, usually incrementing on the higher numbers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As best as I can tell an inside host is hitting an external web page, going through PAT on the firewall, and the firewall is denying the return traffic.  The weird thing is that my users are not complaining of problems with the internet.  So why am I getting tons of these severity 2 syslog messages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I explained that properly.  Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:46:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-question/m-p/334894#M1059622</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2020-02-21T07:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Syslog Question</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-question/m-p/334895#M1059624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on the destination web-server. If the service hosted by the webserver is trying to open a port inbound to your host PCs, that will get denied and logged by the PIX. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2004 18:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-question/m-p/334895#M1059624</guid>
      <dc:creator>thisisshanky</dc:creator>
      <dc:date>2004-11-30T18:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Syslog Question</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-question/m-p/334896#M1059633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's weird though, because this is happening all the time to all sorts of web servers on the internet.  The traffic looks like what you would expect when a web server is responding to an HTML request.  It is sending packets back from port 80 to the firewall's global IP, on one of the high, presumably PAT translated ports.  You would think this would be normal.  But for some reason my syslogs are filled with dropped packets... yet no complaints from the users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2004 19:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-question/m-p/334896#M1059633</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2004-11-30T19:22:07Z</dc:date>
    </item>
  </channel>
</rss>

