<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Akshay, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied/m-p/2772312#M166506</link>
    <description>&lt;P&gt;Akshay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i did a packet capture wizard on the cisco asa but it only showed ingress traffic - no egress but it didnt show much anyway other than an attempt&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I done the packet tracer on the cisco asa and it said that the traffic was being denied by the access-list ie it seen the traffic as denied all and ropped it. &amp;nbsp;I know an acl was applied&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So i checked the routing on the LAN. &amp;nbsp;It turns out this traffic needed to be routed out a different Layer 3 device and routed out the one of the ohter firewalls ( we have 3 on different sites and they are all stand alone). &amp;nbsp;The firewalls all have the same access list&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Bit of a nightmare but routing was the problem and as soon as it routed out the correct firewall then the access list was permitted&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for &amp;nbsp;your help and looking forward to trying this command on Monday&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;....&lt;SPAN&gt;please take the capture with 'cap drop type asp-drop all' and see the output with 'show cap drop | in &amp;lt;source-ip&amp;gt;'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Oct 2015 19:27:06 GMT</pubDate>
    <dc:creator>ohareka70</dc:creator>
    <dc:date>2015-10-30T19:27:06Z</dc:date>
    <item>
      <title>Inbound TCP connection denied</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied/m-p/2772310#M166504</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a server on the corporate network and it has a rule on the firewall to allow it to talk out to another external IP for a winscp transfer over tpc/222&lt;/P&gt;
&lt;P&gt;It was working ok but it stopped this week saying&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 10pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;Inbound TCP connection denied from 10.x.x.x/49578 to 172.x.x.x/222 flags SYN on interface inside&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 10pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 10pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;I am not seeing it hit the firewall except to say that its being denied by an Access Rule&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 10pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 10pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;&lt;/FONT&gt;&lt;FONT color="#000000" face="Calibri"&gt;Any ideas&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 10pt;"&gt;&lt;FONT color="#000000" face="Calibri"&gt;Kevin&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000" face="Times New Roman"&gt; &lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied/m-p/2772310#M166504</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2019-03-12T06:48:41Z</dc:date>
    </item>
    <item>
      <title>Hi Kevin,</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied/m-p/2772311#M166505</link>
      <description>&lt;P&gt;Hi Kevin,&lt;/P&gt;
&lt;P&gt;- Is there any recent changes made on the ASA?&lt;/P&gt;
&lt;P&gt;- when you say you do not see it hitting the firewall; how did you check that? did you take any capture on these ingress and egress interface?&lt;/P&gt;
&lt;P&gt;- could you please take the output of packet-tracer on the ASA.&lt;/P&gt;
&lt;P&gt;'packet-tracer input &amp;lt;source interface&amp;gt; tcp &amp;lt;source-ip&amp;gt; 123445 &amp;lt;destination-ip&amp;gt; 222 detail' and check where it is dropping.&lt;/P&gt;
&lt;P&gt;As you had mentioned it is being denied by ACL, try placing permit acl for this traffic on line 1 on that concerned access-list.&lt;/P&gt;
&lt;P&gt;Also you could take captures on ASA. please take the capture with 'cap drop type asp-drop all' and see the output with 'show cap drop | in &amp;lt;source-ip&amp;gt;'&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please share your findings.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 16:49:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied/m-p/2772311#M166505</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-10-30T16:49:38Z</dc:date>
    </item>
    <item>
      <title>Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied/m-p/2772312#M166506</link>
      <description>&lt;P&gt;Akshay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i did a packet capture wizard on the cisco asa but it only showed ingress traffic - no egress but it didnt show much anyway other than an attempt&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I done the packet tracer on the cisco asa and it said that the traffic was being denied by the access-list ie it seen the traffic as denied all and ropped it. &amp;nbsp;I know an acl was applied&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So i checked the routing on the LAN. &amp;nbsp;It turns out this traffic needed to be routed out a different Layer 3 device and routed out the one of the ohter firewalls ( we have 3 on different sites and they are all stand alone). &amp;nbsp;The firewalls all have the same access list&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Bit of a nightmare but routing was the problem and as soon as it routed out the correct firewall then the access list was permitted&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for &amp;nbsp;your help and looking forward to trying this command on Monday&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;....&lt;SPAN&gt;please take the capture with 'cap drop type asp-drop all' and see the output with 'show cap drop | in &amp;lt;source-ip&amp;gt;'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 19:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied/m-p/2772312#M166506</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2015-10-30T19:27:06Z</dc:date>
    </item>
  </channel>
</rss>

