<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does SYN timeout always tell if issue is at Remote end in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021630#M396537</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the other hand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If looking from local problems, the only one I can think of right now (related to the ASA firewall) is that there is some problem with NAT. For example the connection is getting NATed to wrong NAT IP address which isnt either allowed at the remote end or the NAT IP isnt routable in the network where the connection is destined (For example L2L VPNs)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Oct 2012 19:18:07 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-10-29T19:18:07Z</dc:date>
    <item>
      <title>Does SYN timeout always tell if issue is at Remote end</title>
      <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021624#M396526</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i see fw logs and it has SYN timeout does it always give us indication that issue is at remote end?&lt;/P&gt;&lt;P&gt;i was trying to open vendor site and fw log shows SYN timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does SYN timeout indicate if issue is Local site&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021624#M396526</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T00:15:40Z</dc:date>
    </item>
    <item>
      <title>Does SYN timeout always tell if issue is at Remote end</title>
      <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021625#M396528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That log leads&amp;nbsp; us to think the other host is not replying back to us or the SYN-ACK&amp;nbsp; is getting lost on the internet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could run some captures on the ASA so to make sure you are not receiveing the SYN-ACK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 18:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021625#M396528</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-29T18:41:19Z</dc:date>
    </item>
    <item>
      <title>Does SYN timeout always tell if issue is at Remote end</title>
      <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021626#M396529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If other host is working ok then&amp;nbsp; we should see&amp;nbsp; syn ack&amp;nbsp; in logs to confirm our connection is established with remote host right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 19:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021626#M396529</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-10-29T19:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Does SYN timeout always tell if issue is at Remote end</title>
      <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021627#M396533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the cases (that I've run into) this has been an indication of problem at the remote end. (Well regarding the local firewall it can only be about some remote device since it doesnt see the SYN ACK)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problems can be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Connection is blocked by a remote firewall or firewall somewhere in between&lt;/LI&gt;&lt;LI&gt;Connection is blocked by the remote hosts own firewall (software)&lt;/LI&gt;&lt;LI&gt;Connections SYN arrives to the remote host but a routing problem exists which forward the SYN ACK in a wrong way.&lt;/LI&gt;&lt;LI&gt;Theres an outage in the remote end service you are trying to reach&lt;/LI&gt;&lt;LI&gt;Some other equipment is filtering the traffic in between&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And as Julio said, packet capture is the best way to determine what is happening. You can do this either on ASA or straight on your own computer with Wireshark for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 19:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021627#M396533</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-10-29T19:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Does SYN timeout always tell if issue is at Remote end</title>
      <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021628#M396535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The actual SYN ACK wont show in any firewall logs. Only in packet captures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the ASA firewall sees a SYN coming from the host initiating the connection it will show the log message starting with "Built outbound TCP connection......" (Provided the connection has been allowed by the firewall)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see if the connection got a SYN ACK from the remote host you will need to check the connections state with "show conn" command for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP WAN 173.x.x.x:443 LAN 10.0.0.10:49517, idle 0:00:15, bytes 45295, flags UIO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The flags at the end will tell you in the above case that the connection is U = UP, I = has inbound data, O = has outbound data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To get more info about the different "flags" use the command "show conn detail". At the very start it will list all the "flags"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also as you have seen the message "Teardown TCP connection...:." ending with SYN Timeout reason will tell you that the SYN ACK hasnt been received. The same can also be determined with "show conn" command. With a remote host not responding the flags will naturally be different from the above working situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 19:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021628#M396535</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-10-29T19:11:20Z</dc:date>
    </item>
    <item>
      <title>Does SYN timeout always tell if issue is at Remote end</title>
      <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021629#M396536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should create captures to confirm if you are receiving the SYN-ack&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture capin interface inside match tcp host&amp;nbsp; inside_local_ host _ip&amp;nbsp; host&amp;nbsp; outside_host_ip eq tcp_destination_port&lt;/P&gt;&lt;P&gt;capture capout interface outside match tcp host inside_global_host_ip host outside_host_ip eq tcp_destination_port&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 19:15:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021629#M396536</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-29T19:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Does SYN timeout always tell if issue is at Remote end</title>
      <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021630#M396537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the other hand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If looking from local problems, the only one I can think of right now (related to the ASA firewall) is that there is some problem with NAT. For example the connection is getting NATed to wrong NAT IP address which isnt either allowed at the remote end or the NAT IP isnt routable in the network where the connection is destined (For example L2L VPNs)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 19:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021630#M396537</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-10-29T19:18:07Z</dc:date>
    </item>
    <item>
      <title>Does SYN timeout always tell if issue is at Remote end</title>
      <link>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021631#M396538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Joulio &amp;amp; Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You did very good explanation on&amp;nbsp; SYN Timeout.&lt;/P&gt;&lt;P&gt;I confirmed with vendor that issue is at there side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 19:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-syn-timeout-always-tell-if-issue-is-at-remote-end/m-p/2021631#M396538</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-10-29T19:33:46Z</dc:date>
    </item>
  </channel>
</rss>

