<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5505 blocking return traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-blocking-return-traffic/m-p/2296637#M343554</link>
    <description>&lt;P&gt;Our network has slowed to a crawl and upon investigation it looks as if the ASA5505 is blocking returning traffic. The syslog is full of these from legitimate sites:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2013-08-30 16:58:01 local4.critical 192.168.1.254&amp;nbsp; Aug 30 2013 16:53:38: %ASA-2-106001: Inbound TCP connection denied from 207.131.246.15/80 to aaa.bbb.ccc.xxx/46099 flags PSH ACK&amp;nbsp; on interface outside\n&lt;/P&gt;&lt;P&gt;2013-08-30 16:58:03 local4.critical 192.168.1.254&amp;nbsp; Aug 30 2013 16:53:40: %ASA-2-106001: Inbound TCP connection denied from 207.131.246.15/80 to aaa.bbb.ccc.xxx/31820 flags ACK&amp;nbsp; on interface outside\n&lt;/P&gt;&lt;P&gt;I'm not really sure where to go next so any help would be appreciated.&lt;/P&gt;&lt;P&gt;2013-08-30 16:58:01 local4.critical 192.168.1.254&amp;nbsp; Aug 30 2013 16:53:38: %ASA-2-106001: Inbound TCP connection denied from 207.131.246.15/80 to aaa.bbb.ccc.xxx/46099 flags PSH ACK&amp;nbsp; on interface outside\n&lt;/P&gt;&lt;P&gt;2013-08-30 16:58:03 local4.critical 192.168.1.254&amp;nbsp; Aug 30 2013 16:53:40: %ASA-2-106001: Inbound TCP connection denied from 207.131.246.15/80 to aaa.bbb.ccc.xxx/31820 flags ACK&amp;nbsp; on interface outside\n&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are also using Websense. I have a 'filter except' exception for the above examples (207.131.246.15) for both http and https. I have also reduced MTU to 1472 on the outside just to test. I also upgraded from 256 to 512 memory thinking maybe it was being stressed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to work for a while and then out of nowhere shuts everyone down from wherever they are browsing and then about 20 seconds to a minute later it starts up again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not really sure where to go next.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached (what I hope is) a scrubbed config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:33:39 GMT</pubDate>
    <dc:creator>drice11089</dc:creator>
    <dc:date>2019-03-12T02:33:39Z</dc:date>
    <item>
      <title>ASA5505 blocking return traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-blocking-return-traffic/m-p/2296637#M343554</link>
      <description>&lt;P&gt;Our network has slowed to a crawl and upon investigation it looks as if the ASA5505 is blocking returning traffic. The syslog is full of these from legitimate sites:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2013-08-30 16:58:01 local4.critical 192.168.1.254&amp;nbsp; Aug 30 2013 16:53:38: %ASA-2-106001: Inbound TCP connection denied from 207.131.246.15/80 to aaa.bbb.ccc.xxx/46099 flags PSH ACK&amp;nbsp; on interface outside\n&lt;/P&gt;&lt;P&gt;2013-08-30 16:58:03 local4.critical 192.168.1.254&amp;nbsp; Aug 30 2013 16:53:40: %ASA-2-106001: Inbound TCP connection denied from 207.131.246.15/80 to aaa.bbb.ccc.xxx/31820 flags ACK&amp;nbsp; on interface outside\n&lt;/P&gt;&lt;P&gt;I'm not really sure where to go next so any help would be appreciated.&lt;/P&gt;&lt;P&gt;2013-08-30 16:58:01 local4.critical 192.168.1.254&amp;nbsp; Aug 30 2013 16:53:38: %ASA-2-106001: Inbound TCP connection denied from 207.131.246.15/80 to aaa.bbb.ccc.xxx/46099 flags PSH ACK&amp;nbsp; on interface outside\n&lt;/P&gt;&lt;P&gt;2013-08-30 16:58:03 local4.critical 192.168.1.254&amp;nbsp; Aug 30 2013 16:53:40: %ASA-2-106001: Inbound TCP connection denied from 207.131.246.15/80 to aaa.bbb.ccc.xxx/31820 flags ACK&amp;nbsp; on interface outside\n&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are also using Websense. I have a 'filter except' exception for the above examples (207.131.246.15) for both http and https. I have also reduced MTU to 1472 on the outside just to test. I also upgraded from 256 to 512 memory thinking maybe it was being stressed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to work for a while and then out of nowhere shuts everyone down from wherever they are browsing and then about 20 seconds to a minute later it starts up again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not really sure where to go next.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached (what I hope is) a scrubbed config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-blocking-return-traffic/m-p/2296637#M343554</guid>
      <dc:creator>drice11089</dc:creator>
      <dc:date>2019-03-12T02:33:39Z</dc:date>
    </item>
    <item>
      <title>ASA5505 blocking return traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-blocking-return-traffic/m-p/2296638#M343557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there all sites affected or only the one mentioned? &lt;/P&gt;&lt;P&gt;Do you have 2 uplinks and running into&amp;nbsp; asymmetric routing error?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-14491"&gt;https://supportforums.cisco.com/docs/DOC-14491&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael &lt;BR /&gt; &lt;BR /&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 13:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-blocking-return-traffic/m-p/2296638#M343557</guid>
      <dc:creator>Michael Muenz</dc:creator>
      <dc:date>2013-09-06T13:11:05Z</dc:date>
    </item>
    <item>
      <title>ASA5505 blocking return traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-blocking-return-traffic/m-p/2296639#M343558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I looked for asymmetric routing. We have one other router attached to the internet but that just does VPN to a datacenter and has a specific route set up on the gateway for it. Nothing else should be getting to it other than the single IP address routed to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to be affecting any ip address that needs a persistant connection. As an example I had to download Chrome to a PC this morning and it kept losing connection about 50% through the download. So from my experiments what I can tell is that it makes the first connection no problem, but quickly dies after that and a new connection has to be made. Also when this happens the IP address being accessed shows up in the "SYN Attack" list in ADSM. I have attached an image of the issue. The number one item on the list is a website we use all day long.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/0/5/154501-asdm.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 15:09:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-blocking-return-traffic/m-p/2296639#M343558</guid>
      <dc:creator>drice11089</dc:creator>
      <dc:date>2013-09-06T15:09:56Z</dc:date>
    </item>
  </channel>
</rss>

