<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I had similar issue, and I in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217999#M349993</link>
    <description>&lt;P&gt;I had similar issue, and I fixed it by looking at my &lt;SPAN style="text-decoration: underline;"&gt;security levels&lt;/SPAN&gt;.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2016 13:58:52 GMT</pubDate>
    <dc:creator>Claus Juhl Pedersen</dc:creator>
    <dc:date>2016-09-09T13:58:52Z</dc:date>
    <item>
      <title>inbound TCP connection denied flags SYN on interface inside</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217995#M349989</link>
      <description>&lt;P&gt;Hi people, here again &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a problem with the traffic from the inside network to outside network, traffic is being dropped I don't know why or how to fix it. My set up is a s follow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the outside network there is a router directly connected to the ASA (through the outside network 10.15.1.x), this router creates a different network that is 172.16.35.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd need to access from the internal network to the network 172.16.35.x. I can't, packets are dropped with the message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;A name="wp4768863" target="_blank"&gt;&lt;/A&gt;%ASA-2-106001: Inbound TCP connection denied from&lt;EM&gt; IP_address/port&lt;/EM&gt; to 
&lt;EM&gt;IP_address/port&lt;/EM&gt; flags &lt;SPAN style="color: black;"&gt;tcp_flags&lt;/SPAN&gt; on interface &lt;SPAN style="color: black;"&gt;interface_name&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I created an access rule to permit ip traffic from inside to network 172.16.35.x, which is connected to the outside interface through the router&lt;BR /&gt;Still not working....&lt;BR /&gt;&lt;BR /&gt;Thanks in advance,&lt;BR /&gt;&lt;BR /&gt;Juan&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:42:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217995#M349989</guid>
      <dc:creator>Joan Perez Esteban</dc:creator>
      <dc:date>2019-03-12T01:42:34Z</dc:date>
    </item>
    <item>
      <title>inbound TCP connection denied flags SYN on interface inside</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217996#M349990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Juan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try packet-tracer feature to find out where is problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-5796"&gt;https://supportforums.cisco.com/docs/DOC-5796&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/p.html#wp1878788"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/p.html#wp1878788&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.techrepublic.com/blog/networking/cisco-asa-packet-trace-your-firewall-debug-friend/1482"&gt;http://www.techrepublic.com/blog/networking/cisco-asa-packet-trace-your-firewall-debug-friend/1482&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards &lt;BR /&gt; &lt;BR /&gt;&lt;STRONG&gt;Please rate all helpful posts and close solved questions&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 12:56:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217996#M349990</guid>
      <dc:creator>blau grana</dc:creator>
      <dc:date>2013-05-13T12:56:44Z</dc:date>
    </item>
    <item>
      <title>inbound TCP connection denied flags SYN on interface inside</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217997#M349991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would need to see the configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the error message it would seem to me that this is not a problem with an ACL or NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 13:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217997#M349991</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-13T13:00:43Z</dc:date>
    </item>
    <item>
      <title>inbound TCP connection denied flags SYN on interface inside</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217998#M349992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Blau grana and Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your right, too many time configuring and unconfiguring the box, I miss to add the route in the ASA, is working fine now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Juan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 13:03:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217998#M349992</guid>
      <dc:creator>Joan Perez Esteban</dc:creator>
      <dc:date>2013-05-13T13:03:55Z</dc:date>
    </item>
    <item>
      <title>I had similar issue, and I</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217999#M349993</link>
      <description>&lt;P&gt;I had similar issue, and I fixed it by looking at my &lt;SPAN style="text-decoration: underline;"&gt;security levels&lt;/SPAN&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 13:58:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2217999#M349993</guid>
      <dc:creator>Claus Juhl Pedersen</dc:creator>
      <dc:date>2016-09-09T13:58:52Z</dc:date>
    </item>
    <item>
      <title>Hi there, </title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2218000#M349994</link>
      <description>&lt;P&gt;Hi there,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have the same issue as Juan described. I can access to any websites except anything relate to google (gmail,google search, YouTube).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deny inbound UDP from internal IP/port to 172.217.9.142/443 flags SYN on interface Inside&lt;/P&gt;
&lt;P&gt;any ideas what could cause it?&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lee&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 00:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2218000#M349994</guid>
      <dc:creator>Ly Cao</dc:creator>
      <dc:date>2017-05-04T00:32:15Z</dc:date>
    </item>
    <item>
      <title>Can you run packet tracer for</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2218001#M349995</link>
      <description>&lt;P dir="ltr"&gt;Can you run packet tracer for one of the addresses you are having issues accessing ? It should tell where the packet is getting dropped and why.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 00:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2218001#M349995</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2017-05-04T00:36:49Z</dc:date>
    </item>
    <item>
      <title>Cofee,</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2218002#M349996</link>
      <description>&lt;P&gt;Cofee,&lt;/P&gt;
&lt;P&gt;thanks for the quick response. everything worked fine until today. There's nothing changed in the firewall as well as the internal routing. Strange!. please find attached for trace packet:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Lee&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 00:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2218002#M349996</guid>
      <dc:creator>Ly Cao</dc:creator>
      <dc:date>2017-05-04T00:57:11Z</dc:date>
    </item>
    <item>
      <title>The packet tracer result that</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2218003#M349997</link>
      <description>&lt;P&gt;The packet tracer result that you sent me is dropping the packet due to an ACL configured.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 01:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/2218003#M349997</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2017-05-04T01:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: The packet tracer result that</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/3329420#M349998</link>
      <description>&lt;P&gt;im having the same issue as well ,&amp;nbsp;trying to go from XXXdmz host to YYYYDMZ a web server https&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;2 &lt;/FONT&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;10:18:00&lt;/FONT&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;106001&lt;/FONT&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;10.60.65.1&lt;/FONT&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;25812&lt;/FONT&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;10.11.167.110&lt;/FONT&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;443&lt;/FONT&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Inbound TCP connection denied from 10.60.65.1/25812 to 10.11.167.110/443 flags SYN on interface XXXdmz&lt;/FONT&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XXXdmz is sec level 30&amp;nbsp; as well as the YYYYdmz that in trying to go to. routes are dynamically learned&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt; packet-tracer input ccidmz tcp 10.60.65.1 25812 10.11.167.110 443&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Phase: 1&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Type: CAPTURE&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;MAC Access list&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Phase: 2&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Type: ACCESS-LIST&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Implicit Rule&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;MAC Access list&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Phase: 3&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Type: RECURSIVE-ROUTE-LOOKUP&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Subtype: Recursive Resolve Egress Interface&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;in&amp;nbsp; &amp;nbsp;10.11.167.0&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; via 172.16.160.1, &lt;STRONG&gt;YYYYDMZ&lt;/STRONG&gt; (resolved, timestamp: 528790)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Phase: 4&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Type: RECURSIVE-ROUTE-LOOKUP&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Subtype: Recursive Resolve Egress Interface&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;in&amp;nbsp;&amp;nbsp; 172.16.160.0&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.248 &lt;STRONG&gt;YYYYDMZ&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Phase: 5&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Type: ROUTE-LOOKUP&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Subtype: Resolve Egress Interface&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;found next-hop 172.16.160.1 using egress ifc&amp;nbsp; YYYYDMZ&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Phase: 6&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Type: ACCESS-LIST&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Result: &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;DROP&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Implicit Rule&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Result:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;input-interface: XXXdmz&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;input-status: up&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;input-line-status: up&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;output-interface: &lt;STRONG&gt;YYYYDMZ&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;output-status: up&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;output-line-status: up&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Action: drop&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Drop-reason: (acl-drop)&lt;FONT color="#FF0000"&gt; Flow is denied by configured rule&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2018 16:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/3329420#M349998</guid>
      <dc:creator>JRDIAZ758</dc:creator>
      <dc:date>2018-02-12T16:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: The packet tracer result that</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/4790972#M1098566</link>
      <description>&lt;P&gt;I was experiencing the same issue and was screeching my head for hours (or more like two days). Adding and deleting rules messing up with policies, all for nothing. But finally I have figure it out. The solution was trivial.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As it happens ASA by default will &lt;STRONG&gt;reject anything between the interface if the SECURITY LEVEL is THE SAME&lt;/STRONG&gt; - sick!!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as you will set it up to different values traffic is passed. And you can have 5 on Inside and 45 on DMZ or the vice versa, it does not matter as long as they are different.&lt;/P&gt;&lt;P&gt;So, it is worth to check, and hopefully someone will benefit from this tip.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 08:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/4790972#M1098566</guid>
      <dc:creator>Maciej Wlazlinski</dc:creator>
      <dc:date>2023-03-10T08:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: The packet tracer result that</title>
      <link>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/5228346#M1117784</link>
      <description>&lt;P&gt;That was it. Thanks for posting!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 09:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-tcp-connection-denied-flags-syn-on-interface-inside/m-p/5228346#M1117784</guid>
      <dc:creator>christopherhancock</dc:creator>
      <dc:date>2024-11-25T09:42:05Z</dc:date>
    </item>
  </channel>
</rss>

