<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to connect to remote device in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237690#M350425</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This indeed seems like an issue with remote device (if it is directly connected), either device not listening on 27000 or incorrect DG on device. In a nutshell, there is no response seen to initial SYN sent by client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply captures on ingress and egress and that should clarify this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Sourav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 May 2013 20:35:56 GMT</pubDate>
    <dc:creator>sokakkar</dc:creator>
    <dc:date>2013-05-06T20:35:56Z</dc:date>
    <item>
      <title>Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237689#M350424</link>
      <description>&lt;P&gt;hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unable to connect to device on port 27000.&lt;/P&gt;&lt;P&gt;here are logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: %ASA-6-302013: Built inbound TCP connection 69552007 for X:172.x.x.x/64755 (172.x.x.x/64755) to Y:172.x.x.x/27000 (172.x.x.x/27000)&lt;/P&gt;&lt;P&gt;%ASA-6-302014: Teardown TCP connection 69550694 for X:172.x.x.x/64753 to Y:172.x.x.x/27000 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am coming from x to y interface of asa.&lt;/P&gt;&lt;P&gt;need to confirm if the issue is from remote&amp;nbsp; device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA&amp;nbsp; log shows hit counts&amp;nbsp; while connected to server.&lt;/P&gt;&lt;P&gt;but for return traffic there are no hit counts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237689#M350424</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T01:39:32Z</dc:date>
    </item>
    <item>
      <title>Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237690#M350425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This indeed seems like an issue with remote device (if it is directly connected), either device not listening on 27000 or incorrect DG on device. In a nutshell, there is no response seen to initial SYN sent by client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply captures on ingress and egress and that should clarify this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Sourav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237690#M350425</guid>
      <dc:creator>sokakkar</dc:creator>
      <dc:date>2013-05-06T20:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237691#M350426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to the mentioned log messages would seem that the host isnt responding to the first message that starts the TCP connection negotiation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also with regards to the ACL hitcount. Only the ACL from where the original connection forming comes from gets a hitcount. The return traffic doesnt generate any hitcount.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example in this case the connection from X generates hitcount on the X access-list. IF there was return traffic then it wouldnt produce any hits on the interface Y ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the ASA is a statefull device you dont have to open traffic to both direction. Just the initial direction of the connection forming.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would start by checking the host to which you are trying to connect to for any problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237691#M350426</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-06T20:36:00Z</dc:date>
    </item>
    <item>
      <title>Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237692#M350427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This remote device has return to interface x on some specfic port.&lt;/P&gt;&lt;P&gt;Say we have acl to open&amp;nbsp; port 2700 and xyz on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where&amp;nbsp; port 2700 is connection to device and&amp;nbsp; port xyz is the return traffic coming from that device.&lt;/P&gt;&lt;P&gt;Hope makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for confirming that issue seems to be with remote device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:40:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237692#M350427</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-06T20:40:39Z</dc:date>
    </item>
    <item>
      <title>Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237693#M350428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi sourav,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for confirming this that issue is with remote device.&lt;/P&gt;&lt;P&gt;Can you please let me know what config&amp;nbsp; i need to apply for packet captures?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237693#M350428</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-06T20:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237694#M350429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if I understood you correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in a nutshell, you only open ports in the interface ACL behind which the connections are initiated from. You wont have to take into account the return traffic of that said connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If both devices open/initiate connections then you naturally have to allow connections on both ACLs. But to be honest there arent that many situations where you would run into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237694#M350429</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-06T20:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237695#M350430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check these links which explains captures in detail:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-17345"&gt;https://supportforums.cisco.com/docs/DOC-17345&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-17814"&gt;https://supportforums.cisco.com/docs/DOC-17814&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Sourav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237695#M350430</guid>
      <dc:creator>sokakkar</dc:creator>
      <dc:date>2013-05-06T20:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237696#M350431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure the capture with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list CAPTURE permit ip host &lt;X host=""&gt; host &lt;Y host=""&gt;&lt;/Y&gt;&lt;/X&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list CAPTURE permit ip host &lt;Y host=""&gt; host &lt;X host=""&gt;&lt;/X&gt;&lt;/Y&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;capture CAPTURE type raw-data access-list CAPTURE interface X buffer 5000000 circular-buffer&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show capture&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see if any traffic has hit the capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show capture CAPTURE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To view the contents of the capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:46:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237696#M350431</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-06T20:46:40Z</dc:date>
    </item>
    <item>
      <title>Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237697#M350432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We open two&amp;nbsp; ports on ASA&amp;nbsp; for user to access the remote device.&lt;/P&gt;&lt;P&gt;on one port connection is build and on other&amp;nbsp; port as per user return traffic comes so thats why second&amp;nbsp; port is needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237697#M350432</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-06T20:48:19Z</dc:date>
    </item>
    <item>
      <title>Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237698#M350433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i will do that and will update you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237698#M350433</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-06T20:49:34Z</dc:date>
    </item>
    <item>
      <title>Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237699#M350434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tomorrow i will test with Packet capture as the access to device is not working can you tell me what info i should look into&lt;/P&gt;&lt;P&gt;when i run sh capture name?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As output can be long?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 01:04:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237699#M350434</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-15T01:04:29Z</dc:date>
    </item>
    <item>
      <title>Unable to connect to remote device</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237700#M350437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue is fixed now.&lt;/P&gt;&lt;P&gt;It was routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 18:03:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-connect-to-remote-device/m-p/2237700#M350437</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-16T18:03:46Z</dc:date>
    </item>
  </channel>
</rss>

