<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Duplicate TCP SYN error SYSLOG ID 419002 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126983#M392707</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I support a unit where we have 2 ASA's acting as their firewalls between their internal, DMZ and external network. One ASA is active and one is passive. I have setup alot of access rules for access of devices to servers from internal to DMZ, DMZ to external etc...&amp;nbsp; I have an issue with one webserver.&amp;nbsp; The webserver has a DMZ leg and an external NIC too.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users on the internal network need to get to the DMZ&amp;nbsp; NIC which i have setup and is working fine.&amp;nbsp; There is also an external web URL whcih external users type into to get to the webserver from externally.&amp;nbsp; On the ASA i have added the webservers dmz address and external address as objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the access rule for the outside communication is where i have the problem.&amp;nbsp; I have an access rule on the outside interface which is to permit ip from any source to that webserver using its external address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when i try and test this by going to the external address URL it does not connect and i get a load of Duplicate TCP SYN attacks which i just cannot resolve and do not understand where these are coming from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get error "Duplicate TCP SYN from outside xx.xx.xx.xx/21963 to outside xx.xx.xx.xx/80 with different initial sequence number"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the numerous error logs the source IP and source port is always exactly the same.&amp;nbsp; I understand the error normally could mean a spoof but i dont know how this could happen.&amp;nbsp; Also i understand it could be a routing loop somewhere but again i dont know where to look for a routing loop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice on how to troubleshoot would be appreciated.&amp;nbsp; Please Note I have an identical webserbver just with different IPs that seems to be working fine, has the same access rules on the ASA.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:47:57 GMT</pubDate>
    <dc:creator>rickysahni</dc:creator>
    <dc:date>2019-03-12T00:47:57Z</dc:date>
    <item>
      <title>Duplicate TCP SYN error SYSLOG ID 419002</title>
      <link>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126983#M392707</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I support a unit where we have 2 ASA's acting as their firewalls between their internal, DMZ and external network. One ASA is active and one is passive. I have setup alot of access rules for access of devices to servers from internal to DMZ, DMZ to external etc...&amp;nbsp; I have an issue with one webserver.&amp;nbsp; The webserver has a DMZ leg and an external NIC too.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users on the internal network need to get to the DMZ&amp;nbsp; NIC which i have setup and is working fine.&amp;nbsp; There is also an external web URL whcih external users type into to get to the webserver from externally.&amp;nbsp; On the ASA i have added the webservers dmz address and external address as objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the access rule for the outside communication is where i have the problem.&amp;nbsp; I have an access rule on the outside interface which is to permit ip from any source to that webserver using its external address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when i try and test this by going to the external address URL it does not connect and i get a load of Duplicate TCP SYN attacks which i just cannot resolve and do not understand where these are coming from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get error "Duplicate TCP SYN from outside xx.xx.xx.xx/21963 to outside xx.xx.xx.xx/80 with different initial sequence number"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the numerous error logs the source IP and source port is always exactly the same.&amp;nbsp; I understand the error normally could mean a spoof but i dont know how this could happen.&amp;nbsp; Also i understand it could be a routing loop somewhere but again i dont know where to look for a routing loop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice on how to troubleshoot would be appreciated.&amp;nbsp; Please Note I have an identical webserbver just with different IPs that seems to be working fine, has the same access rules on the ASA.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126983#M392707</guid>
      <dc:creator>rickysahni</dc:creator>
      <dc:date>2019-03-12T00:47:57Z</dc:date>
    </item>
    <item>
      <title>Duplicate TCP SYN error SYSLOG ID 419002</title>
      <link>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126984#M392708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ricky,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the ASA NAT;s that server to a specific IP on the inside and also to a public ip address on the outside....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when you connect from outside you get that error message.. Does that happen with all the connection attempts??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 17:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126984#M392708</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-16T17:49:39Z</dc:date>
    </item>
    <item>
      <title>Duplicate TCP SYN error SYSLOG ID 419002</title>
      <link>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126985#M392711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi thanks for your reply.&amp;nbsp; I resolved the issue, was missing the NAT rule for the ASA to NAT the external address to its DMZ address... d'oh!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 11:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126985#M392711</guid>
      <dc:creator>rickysahni</dc:creator>
      <dc:date>2013-01-17T11:56:22Z</dc:date>
    </item>
    <item>
      <title>Duplicate TCP SYN error SYSLOG ID 419002</title>
      <link>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126986#M392714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great to hear that..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark the question as answered so future users can learn from this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 18:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/duplicate-tcp-syn-error-syslog-id-419002/m-p/2126986#M392714</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-17T18:35:38Z</dc:date>
    </item>
  </channel>
</rss>

