<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCP SYN Timeout ASA5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305816#M344653</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, i cant reach anything.&lt;/P&gt;&lt;P&gt;When i do a packet trace it shows i should be able to connect. Nothing in its way that blocking traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Aug 2013 09:04:45 GMT</pubDate>
    <dc:creator>ruud.manders</dc:creator>
    <dc:date>2013-08-15T09:04:45Z</dc:date>
    <item>
      <title>TCP SYN Timeout ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305812#M344648</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Cisco877 DSL router wich is in bridge mode so the ASA5505 gets the public IP.&lt;/P&gt;&lt;P&gt;This works, however nothing else is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm unable to access the Internet, i cant access the ASA on the Outside Interface.&lt;/P&gt;&lt;P&gt;All results in SYN errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm stuck and would appriciate some help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ruud&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config Cisco877&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bridge irb&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;interface ATM0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no atm ilmi-keepalive&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;interface ATM0.1 point-to-point&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; atm route-bridged ip&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; pvc 0/35 &lt;/P&gt;&lt;P&gt;&amp;nbsp; encapsulation aal5snap&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet2&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet3&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;bridge 1 protocol ieee&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;bridge 1 route ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config ASA5505&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan11&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address dhcp setroute &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any4 any4 &lt;/P&gt;&lt;P&gt;access-list global_access extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list global_access extended permit icmp any4 any4 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit icmp any4 any4 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-713.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic any interface&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group global_access global&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;&lt;P&gt;crypto ca trustpool policy&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.100-192.168.1.200 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;ssl encryption aes256-sha1 aes128-sha1 rc4-sha1&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:25:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305812#M344648</guid>
      <dc:creator>ruud.manders</dc:creator>
      <dc:date>2019-03-12T02:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYN Timeout ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305813#M344650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your ASA tries to get it's outside IP by DHCP, but it has to use PPPOE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080ab7ce9.shtml" rel="nofollow"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080ab7ce9.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW: Using an IOS router as a dsl modem is really a waste of ressources. A cheap dsl-modem would be fine for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 08:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305813#M344650</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-08-15T08:09:05Z</dc:date>
    </item>
    <item>
      <title>TCP SYN Timeout ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305814#M344651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA is getting the right address using DHCP.&lt;/P&gt;&lt;P&gt;I dont have a username and password so i cant use PPPoE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Cisco 877 was the device i used before to access the Internet with this DSL line.&lt;/P&gt;&lt;P&gt;There was no need for PPPoE.&lt;/P&gt;&lt;P&gt;See the old config of the 877 below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;security authentication failure rate 3 log&lt;/P&gt;&lt;P&gt;security passwords min-length 6&lt;/P&gt;&lt;P&gt;logging buffered 51200&lt;/P&gt;&lt;P&gt;logging console critical&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login local_authen local&lt;/P&gt;&lt;P&gt;aaa authorization exec local_author local &lt;/P&gt;&lt;P&gt;!&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;crypto pki certificate chain tti&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;crypto pki certificate chain TP-self-signed-3629992121&lt;/P&gt;&lt;P&gt; certificate self-signed 01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;dot11 syslog&lt;/P&gt;&lt;P&gt;no ip source-route&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip dhcp use vrf connected&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.100.1 192.168.100.9&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.100.16 192.168.100.254&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;ip dhcp pool Internet-pool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; import all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; network 10.10.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; default-router 10.10.10.1 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; dns-server 217.149.192.6 217.149.196.6 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; domain-name uni.nl&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip vrf Secure&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip bootp server&lt;/P&gt;&lt;P&gt;ip domain name uni.nl&lt;/P&gt;&lt;P&gt;ip inspect name inspect-out http urlfilter audit-trail off&lt;/P&gt;&lt;P&gt;ip inspect name inspect-in http urlfilter audit-trail off&lt;/P&gt;&lt;P&gt;ip urlfilter exclusive-domain permit .windowsupdate.com&lt;/P&gt;&lt;P&gt;ip urlfilter exclusive-domain permit .microsoft.com&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;multilink bundle-name authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tcp synwait-time 10&lt;/P&gt;&lt;P&gt;ip ssh time-out 60&lt;/P&gt;&lt;P&gt;ip ssh authentication-retries 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Null0&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface ATM0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; no atm ilmi-keepalive&lt;/P&gt;&lt;P&gt; dsl operating-mode auto &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface ATM0.1 point-to-point&lt;/P&gt;&lt;P&gt; ip address dhcp&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; atm route-bridged ip&lt;/P&gt;&lt;P&gt; pvc 0/35 &lt;/P&gt;&lt;P&gt;&amp;nbsp; encapsulation aal5snap&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; switchport access vlan 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1&lt;/P&gt;&lt;P&gt; switchport access vlan 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet2&lt;/P&gt;&lt;P&gt; switchport access vlan 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet3&lt;/P&gt;&lt;P&gt; description SecureNetwerk&lt;/P&gt;&lt;P&gt; switchport access vlan 20&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan20&lt;/P&gt;&lt;P&gt; ip address 192.168.100.1 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip inspect inspect-in in&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan10&lt;/P&gt;&lt;P&gt; ip address 10.10.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip access-group 100 in&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 ATM0.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http access-class 5&lt;/P&gt;&lt;P&gt;ip http authentication local&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface ATM0.1 overload&lt;/P&gt;&lt;P&gt;ip nat inside source static esp 10.10.10.4 interface ATM0&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 10.10.10.2 443 85.223.x.y 443 extendable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 08:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305814#M344651</guid>
      <dc:creator>ruud.manders</dc:creator>
      <dc:date>2013-08-15T08:22:25Z</dc:date>
    </item>
    <item>
      <title>TCP SYN Timeout ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305815#M344652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;The ASA is getting the right address using DHCP.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I dont have a username and password so i cant use PPPoE.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;oh, I wasn't aware of any DSL-provider using DHCP. Only saw PPPoE ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you reach any destinations (inside or outside) *from* the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 08:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305815#M344652</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-08-15T08:52:15Z</dc:date>
    </item>
    <item>
      <title>TCP SYN Timeout ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305816#M344653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, i cant reach anything.&lt;/P&gt;&lt;P&gt;When i do a packet trace it shows i should be able to connect. Nothing in its way that blocking traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 09:04:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305816#M344653</guid>
      <dc:creator>ruud.manders</dc:creator>
      <dc:date>2013-08-15T09:04:45Z</dc:date>
    </item>
    <item>
      <title>TCP SYN Timeout ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305817#M344654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;No, i cant reach anything.&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not even an internal system? How is your internal setup? And post the output of "show route".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 09:30:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305817#M344654</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-08-15T09:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYN Timeout ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305818#M344655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When your ASA gets an IP from DHCP, it also gets a gateway address. Can you ping the gateway address from the outside interface of the ASA?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 10:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305818#M344655</guid>
      <dc:creator>SHAWN EFTINK</dc:creator>
      <dc:date>2013-08-15T10:29:25Z</dc:date>
    </item>
    <item>
      <title>TCP SYN Timeout ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305819#M344656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps the provider limited access to the MAC address of ATM device, since there's no authentication with DHCP? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael &lt;BR /&gt; &lt;BR /&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 08:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-syn-timeout-asa5505/m-p/2305819#M344656</guid>
      <dc:creator>Michael Muenz</dc:creator>
      <dc:date>2013-08-16T08:24:05Z</dc:date>
    </item>
  </channel>
</rss>

