<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA - SYN timeout in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-syn-timeout/m-p/1684524#M556694</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ramkumar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a lot of generalities in your post. Usually it is best to include specifics to get an accurate response. Otherwise, we're all just guessing. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet captures run on each interface of the ASA will tell you if the ASA is receiving the SYN and if it is being forwarded. It will also tell you if a SYN/ACK is being received in response. I would suggest running simultaneous captures on both the inside and outside interfaces to see if the ASA is dropping your SYN or if the problem is elsewhere. If the ASA is dropping the packets, look at your syslogs at informational or debugging level to determine why. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-1222"&gt;Packet capture help.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 May 2011 15:59:25 GMT</pubDate>
    <dc:creator>brquinn</dc:creator>
    <dc:date>2011-05-04T15:59:25Z</dc:date>
    <item>
      <title>ASA - SYN timeout</title>
      <link>https://community.cisco.com/t5/network-security/asa-syn-timeout/m-p/1684523#M556693</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing - SYN timeout issue while accessing an URL via ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My network setup,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have MPLS and VPN (with local breakout), my intranet traffic goes via MPLS and internet traffic goes via ASA. When MPLS fails intranet and internet is traffic routed via VPN. When VPN fails both intranet and internet is routed via MPLS. I have standard ACL's in place, implicit deny at the end. While accessing a particular URL, iam getting syn timeout. but its working in other sites with similar setup(used tracking).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some of my analysis,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Added a sepererate ACL for permitting any any IP and applied to the inside interface, but still the same issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help !&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syn-timeout/m-p/1684523#M556693</guid>
      <dc:creator>Ramkumar P</dc:creator>
      <dc:date>2019-03-11T20:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - SYN timeout</title>
      <link>https://community.cisco.com/t5/network-security/asa-syn-timeout/m-p/1684524#M556694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ramkumar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a lot of generalities in your post. Usually it is best to include specifics to get an accurate response. Otherwise, we're all just guessing. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet captures run on each interface of the ASA will tell you if the ASA is receiving the SYN and if it is being forwarded. It will also tell you if a SYN/ACK is being received in response. I would suggest running simultaneous captures on both the inside and outside interfaces to see if the ASA is dropping your SYN or if the problem is elsewhere. If the ASA is dropping the packets, look at your syslogs at informational or debugging level to determine why. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-1222"&gt;Packet capture help.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 May 2011 15:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syn-timeout/m-p/1684524#M556694</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-05-04T15:59:25Z</dc:date>
    </item>
  </channel>
</rss>

