<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,To add to Jeff's comment , in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/getting-deny-tcp-no-connection-after-session-teardown/m-p/2674376#M191695</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;To add to Jeff's comment , Once you know why the initial reply is a RESET , these No connections syslog would go away.&lt;/P&gt;&lt;P&gt;As the Other end is still trying to send DATA even though the connections has been removed after the RESET is received on the ASA device.&lt;/P&gt;&lt;P&gt;Notice , the same source port for the RESET log and the no connection log. IO think this is the probable issue and try to find the reason for the RESET and that should resolve the issue.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Thu, 14 May 2015 05:47:49 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2015-05-14T05:47:49Z</dc:date>
    <item>
      <title>Getting 'Deny TCP (no connection)' after session Teardown</title>
      <link>https://community.cisco.com/t5/network-security/getting-deny-tcp-no-connection-after-session-teardown/m-p/2674374#M191693</link>
      <description>&lt;P&gt;I've been having a problem with getting microsoft-ds (445/tcp) connectivity between servers at two different sites.&amp;nbsp; It looks like the routing and the firewall rules are setup to allow the traffic, but when I attempt to connect, I'm getting the following behavior:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May 12 14:42:54 myfw %ASA-6-302013: Built inbound TCP connection 225654645 for lab-transit:10.25.240.36/62318 (10.25.240.36/62318) to transit:10.70.10.53/445 (10.70.10.53/445)&lt;BR /&gt;May 12 14:43:14 myfw %ASA-6-302014: Teardown TCP connection 225654645 for lab-transit:10.25.240.36/62318 to transit:10.70.10.53/445 duration 0:00:19 bytes 4094 TCP Reset-I&lt;BR /&gt;May 12 14:43:14 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:25 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:26 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:27 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:28 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:29 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:30 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:31 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:32 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:33 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:34 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags ACK&amp;nbsp; on interface lab-transit&lt;BR /&gt;May 12 14:43:35 myfw %ASA-6-106015: Deny TCP (no connection) from 10.25.240.36/62318 to 10.70.10.53/445 flags RST ACK&amp;nbsp; on interface lab-transit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The time between build and teardown is consistently 19 seconds and this pattern keeps repeating.&amp;nbsp; Has anyone seen this before?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:55:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-deny-tcp-no-connection-after-session-teardown/m-p/2674374#M191693</guid>
      <dc:creator>jnaglich</dc:creator>
      <dc:date>2019-03-12T05:55:13Z</dc:date>
    </item>
    <item>
      <title>I'd setup a captures on the</title>
      <link>https://community.cisco.com/t5/network-security/getting-deny-tcp-no-connection-after-session-teardown/m-p/2674375#M191694</link>
      <description>&lt;P&gt;I'd setup a captures on the transit and lab-transit interfaces and review both of them in Wireshark. &amp;nbsp;The reset is coming from one side or the other, not from the firewall. &amp;nbsp;Once you determine which one is sending the reset, you can look deeper into that server to find out why.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2015 17:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-deny-tcp-no-connection-after-session-teardown/m-p/2674375#M191694</guid>
      <dc:creator>JEFF SPRADLING</dc:creator>
      <dc:date>2015-05-12T17:46:01Z</dc:date>
    </item>
    <item>
      <title>Hi,To add to Jeff's comment ,</title>
      <link>https://community.cisco.com/t5/network-security/getting-deny-tcp-no-connection-after-session-teardown/m-p/2674376#M191695</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;To add to Jeff's comment , Once you know why the initial reply is a RESET , these No connections syslog would go away.&lt;/P&gt;&lt;P&gt;As the Other end is still trying to send DATA even though the connections has been removed after the RESET is received on the ASA device.&lt;/P&gt;&lt;P&gt;Notice , the same source port for the RESET log and the no connection log. IO think this is the probable issue and try to find the reason for the RESET and that should resolve the issue.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 05:47:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-deny-tcp-no-connection-after-session-teardown/m-p/2674376#M191695</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-14T05:47:49Z</dc:date>
    </item>
  </channel>
</rss>

