<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Return traffic being blocked in FTD firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246400#M1118719</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;Is anyone here also experience this kind of issue on the FTD?&amp;nbsp; we notice that some return traffic being blocked on the FTD.&lt;/P&gt;
&lt;P&gt;Thanks for the answer!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2025 13:06:33 GMT</pubDate>
    <dc:creator>mjrosana02</dc:creator>
    <dc:date>2025-01-13T13:06:33Z</dc:date>
    <item>
      <title>Return traffic being blocked in FTD firewall</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246400#M1118719</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;Is anyone here also experience this kind of issue on the FTD?&amp;nbsp; we notice that some return traffic being blocked on the FTD.&lt;/P&gt;
&lt;P&gt;Thanks for the answer!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 13:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246400#M1118719</guid>
      <dc:creator>mjrosana02</dc:creator>
      <dc:date>2025-01-13T13:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic being blocked in FTD firewall</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246402#M1118720</link>
      <description>&lt;P&gt;Did you check ""show conn"" to see if there active conn in ftd for retrun traffic&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 12:46:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246402#M1118720</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-13T12:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic being blocked in FTD firewall</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246462#M1118724</link>
      <description>&lt;P&gt;What indicators are you seeing to lead to believe this is the case?&lt;/P&gt;
&lt;P&gt;Have you confirmed the routing is symmetric (return traffic coming via the same interface via which it leaves)?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 13:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246462#M1118724</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-01-13T13:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic being blocked in FTD firewall</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246702#M1118762</link>
      <description>&lt;P&gt;Please provide logs and if possible packet captures showing this behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 00:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246702#M1118762</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-14T00:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic being blocked in FTD firewall</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246707#M1118763</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mjrosana02_0-1736818342693.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237499i8FC58A9ACF495C0C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mjrosana02_0-1736818342693.png" alt="mjrosana02_0-1736818342693.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here is the sample logs, From the existing rule the source is 172.16.x.x network and the destination is 192.168.24.40 on port 8443, there is no issue from this direction. But we are seeing these logs where 192.168.24.40 is communicating back to 172.16.x.x using port 8443 but the destination is the random ports.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 01:38:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246707#M1118763</guid>
      <dc:creator>mjrosana02</dc:creator>
      <dc:date>2025-01-14T01:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic being blocked in FTD firewall</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246708#M1118764</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1481123"&gt;@ccieexpert&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Good day!&lt;BR /&gt;Please refer to my comments above.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 01:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246708#M1118764</guid>
      <dc:creator>mjrosana02</dc:creator>
      <dc:date>2025-01-14T01:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic being blocked in FTD firewall</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246749#M1118765</link>
      <description>&lt;P&gt;that doesnt help as it only shows the reverse packets that are blocked..&lt;/P&gt;
&lt;P&gt;first question is there any issue ? or you are just checking why they are happening ?&lt;/P&gt;
&lt;P&gt;You should get a syslog of the entire flow from start to finish as shown in the below link.&lt;/P&gt;
&lt;P&gt;That will help to see when the CONN was built and when it was teardown.. It is possible that a conn was reset/torn down by the firewall,&amp;nbsp; and then a return packet came after that in the reverse direction, thus my question is it affecting anything..&lt;/P&gt;
&lt;P&gt;Please get us the syslog/log for the sourde/destination flow, which allow us more insight.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.lammle.com/post/cisco-firepower-ftd-syslog-messages-and-how-to-see-cisco-ftd-lina-events/" target="_blank"&gt;https://www.lammle.com/post/cisco-firepower-ftd-syslog-messages-and-how-to-see-cisco-ftd-lina-events/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 03:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246749#M1118765</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-14T03:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic being blocked in FTD firewall</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246766#M1118766</link>
      <description>&lt;P&gt;That's return traffic which hits the firewall after the session has already been closed, that is the firewall doesn't find a xlate for those sessions, I suppose this can happen for many reasons, duplicated packets, high latency, network issues, server issues etc..&lt;/P&gt;&lt;P&gt;Nothing to be worried about usually&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 05:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-being-blocked-in-ftd-firewall/m-p/5246766#M1118766</guid>
      <dc:creator>Massimo Baschieri</dc:creator>
      <dc:date>2025-01-14T05:08:01Z</dc:date>
    </item>
  </channel>
</rss>

