<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA/FWSM: Abundance of SYN timeouts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-fwsm-abundance-of-syn-timeouts/m-p/1843237#M491380</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hope you don't mind a gentlewonan's response &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;SYN timeout syslogs are generated when the firewall doesn't receive a response for SYN that it passed through. It appears that the server may be responding back with a SYN ACK late (after 20 seconds ) or not at all.&lt;/P&gt;&lt;P&gt;If it responds late, then you would also see syslog 106015 messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Dec 2011 14:11:25 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2011-12-09T14:11:25Z</dc:date>
    <item>
      <title>ASA/FWSM: Abundance of SYN timeouts</title>
      <link>https://community.cisco.com/t5/network-security/asa-fwsm-abundance-of-syn-timeouts/m-p/1843236#M491379</link>
      <description>&lt;P&gt;Gentlemen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall'ing and FW-forensic is not my primary area of expertise, so forgive my ignorance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When browsing through the collected syslogs from our firewalls (FWSM/ASA), I'm seeing an abundance of SYN Timeouts. There's no specific pattern here, e.g. specific host or service, time of day etc. I can pick any day of the week and select a random host/service and simply search for the string "SYN" and I will almost surely get a significant number of hits.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I'm not really looking for solution, as we've pretty much ruled out the possibility of misconfiguration. We've gone through potential problems with regards to TCP-connections limitations, timeout values, routing etc. But nothing seems to be misconfigured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question to you gentlemen is: Is what I'm seeing typical or even expected behaviour? Since my server- or application teams are not screaming their lungs out with "slow network", this apparently does not cause severe performance degredation. I'm just surprised by the volume of SYN timeouts, but then again, browsing through the FW-syslogs is not really part of my everyday work. Can something like this be the result of theh fact that the volume of application traffic exceeds the capacity of the servers and that this i more a symptom of applications and/or server performance, rather than a network related issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;/Ulrich&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-fwsm-abundance-of-syn-timeouts/m-p/1843236#M491379</guid>
      <dc:creator>Ulrich Hansen</dc:creator>
      <dc:date>2019-03-11T22:00:54Z</dc:date>
    </item>
    <item>
      <title>ASA/FWSM: Abundance of SYN timeouts</title>
      <link>https://community.cisco.com/t5/network-security/asa-fwsm-abundance-of-syn-timeouts/m-p/1843237#M491380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hope you don't mind a gentlewonan's response &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;SYN timeout syslogs are generated when the firewall doesn't receive a response for SYN that it passed through. It appears that the server may be responding back with a SYN ACK late (after 20 seconds ) or not at all.&lt;/P&gt;&lt;P&gt;If it responds late, then you would also see syslog 106015 messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Dec 2011 14:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-fwsm-abundance-of-syn-timeouts/m-p/1843237#M491380</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-12-09T14:11:25Z</dc:date>
    </item>
    <item>
      <title>ASA/FWSM: Abundance of SYN timeouts</title>
      <link>https://community.cisco.com/t5/network-security/asa-fwsm-abundance-of-syn-timeouts/m-p/1843238#M491384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kureli,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't mind a gentlewomans reply at all &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll take another look at the syslog and see, if the 106015-msg appears frequently as well.&lt;/P&gt;&lt;P&gt;Thanks for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Ulrich&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Dec 2011 14:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-fwsm-abundance-of-syn-timeouts/m-p/1843238#M491384</guid>
      <dc:creator>Ulrich Hansen</dc:creator>
      <dc:date>2011-12-09T14:56:09Z</dc:date>
    </item>
  </channel>
</rss>

