<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SYN ACK error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syn-ack-error/m-p/2347951#M344883</link>
    <description>&lt;P&gt;Hi folks, hoping someone out there can point out why I am having a few difficulties on my network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2 seperate internet connections protected by ASA Firewalls, one in our main datacenter and another in our DR datacenter. I have drawn a very simplistic diagram at &lt;SPAN style="font-size: 10pt;"&gt;&lt;A href="http://postimg.org/image/qcmrulnrx/" target="_blank"&gt;http://postimg.org/image/qcmrulnrx/&lt;/A&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;please take a look.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I have a problem when I try to translate one of our public IP addresses being routed to our site B firewall. Say I have a website on server A, internal address 192.168.12.51. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I want to make it publically available via one of the IP's currently routed to our DR firewall, so i create a rule to Xlate from 118.220.X.X to 192.168.12.51&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;However when i try to initiate a connection from an external machine - say &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;68.232.X.X and &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;examine the traffic using ASDM i can see the built inbound tcp connection from the public IP to the internal IP is ok. But when i then filter based on the internal IP of the server i can see the SYN timeout error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown TCP connection 20738497 for outside:68.232.X.X/40717 to inside:192.168.12.51/80 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I change the Public IP to one being routed to Firewall A, it works with no issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A couple of important points, which could be affecting this (perhaps there is a circular routing issue here?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The catalyst 3750 has a default route to pass any traffic that it doesnt have a routing table entry for to the firewall in site A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server A's default gateway is to the VLAN12 interface on the catalyst 3750&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The catalyst 3650 (site B) has some static routes in there to route the 118.220.X.X/29 network to FIrewall B (19.168.201.20)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its probably something very simple, any ideas?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:24:26 GMT</pubDate>
    <dc:creator>Nick Currie</dc:creator>
    <dc:date>2019-03-12T02:24:26Z</dc:date>
    <item>
      <title>SYN ACK error</title>
      <link>https://community.cisco.com/t5/network-security/syn-ack-error/m-p/2347951#M344883</link>
      <description>&lt;P&gt;Hi folks, hoping someone out there can point out why I am having a few difficulties on my network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2 seperate internet connections protected by ASA Firewalls, one in our main datacenter and another in our DR datacenter. I have drawn a very simplistic diagram at &lt;SPAN style="font-size: 10pt;"&gt;&lt;A href="http://postimg.org/image/qcmrulnrx/" target="_blank"&gt;http://postimg.org/image/qcmrulnrx/&lt;/A&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;please take a look.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I have a problem when I try to translate one of our public IP addresses being routed to our site B firewall. Say I have a website on server A, internal address 192.168.12.51. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I want to make it publically available via one of the IP's currently routed to our DR firewall, so i create a rule to Xlate from 118.220.X.X to 192.168.12.51&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;However when i try to initiate a connection from an external machine - say &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;68.232.X.X and &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;examine the traffic using ASDM i can see the built inbound tcp connection from the public IP to the internal IP is ok. But when i then filter based on the internal IP of the server i can see the SYN timeout error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown TCP connection 20738497 for outside:68.232.X.X/40717 to inside:192.168.12.51/80 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I change the Public IP to one being routed to Firewall A, it works with no issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A couple of important points, which could be affecting this (perhaps there is a circular routing issue here?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The catalyst 3750 has a default route to pass any traffic that it doesnt have a routing table entry for to the firewall in site A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server A's default gateway is to the VLAN12 interface on the catalyst 3750&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The catalyst 3650 (site B) has some static routes in there to route the 118.220.X.X/29 network to FIrewall B (19.168.201.20)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its probably something very simple, any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syn-ack-error/m-p/2347951#M344883</guid>
      <dc:creator>Nick Currie</dc:creator>
      <dc:date>2019-03-12T02:24:26Z</dc:date>
    </item>
    <item>
      <title>SYN ACK error</title>
      <link>https://community.cisco.com/t5/network-security/syn-ack-error/m-p/2347952#M344884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your problem is most likely asymmetric routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your server at Site A has its default route towards the Site A firewall and your are trying to NAT the Server to a Site B public IP address, this is what will happen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A user on the Internet connects to the Site B public IP address of Site A server&lt;/LI&gt;&lt;LI&gt;TCP connections TCP SYN arrives on the server at Site A&lt;/LI&gt;&lt;LI&gt;Site A server replies with TCP SYN ACK but sends this through Site A local firewall&lt;/LI&gt;&lt;LI&gt;Site A firewall blocks the TCP SYN ACK with a message "Deny (no connection)" or something to that direction.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words the server cant negotiate the TCP connection up since there is asymmetric routing. To use the Site B public IP address for Site A server you would probably have to configure somekind of Policy Based Routing on Site A LAN router to forward the servers traffic to Site B while rest of the server network at Site A use its normal Site A default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 07:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syn-ack-error/m-p/2347952#M344884</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-12T07:05:36Z</dc:date>
    </item>
  </channel>
</rss>

