<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Nat Problem.. Need Ur Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654501#M568528</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Siddharth,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Pls. refer this link: &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-8982"&gt;https://supportforums.cisco.com/docs/DOC-8982&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove http inspection if enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; .&lt;/P&gt;&lt;P&gt;&amp;nbsp; .&lt;BR /&gt;&amp;nbsp; inspect http&amp;nbsp; -----------------------&amp;gt; remove this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 29 Jan 2011 13:18:30 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2011-01-29T13:18:30Z</dc:date>
    <item>
      <title>PIX Nat Problem.. Need Ur Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654500#M568527</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;DIV id="main"&gt;&lt;DIV id="paneshell"&gt;&lt;DIV id="shellcontent"&gt;&lt;DIV id="aui-3-2-0-112828"&gt;&lt;DIV class=" message&amp;nbsp; content" id="aui-3-2-0-112831"&gt;&lt;DIV class="msg-body inner&amp;nbsp; undoreset" id="aui-3-2-0-114020"&gt;&lt;DIV id="yiv999507258"&gt;&lt;DIV id="aui-3-2-0-114019"&gt;&lt;SPAN id="aui-3-2-0-114018"&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;&lt;DIV style="text-align: left;"&gt;&lt;BR /&gt;Problem with the PIX 525e while&amp;nbsp; "NATTING " .&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Reference Topology : &lt;/DIV&gt;&lt;BR /&gt;ISP (172.16.21.1)&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;|&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;|&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;|&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;|&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;Ethernet0 (172.16.21.34 /24)&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;--------------&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt; PIX 525e &lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;--------------&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;Giga0/0&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;(10.177.182.1 /24)&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;|&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;|&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;|&lt;/DIV&gt;&lt;DIV align="center" class="yiv999507258MsoNormal"&gt;LAN Users&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;DNS provided by ISP : 172.16.0.1&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;Static IP addresses are assigned to LAN users with DNS : 172.16.0.1&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN class="yiv999507258"&gt;&lt;SPAN class="yiv999507258" style="font-size: 14pt;"&gt;PIX Details:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;Hardware:&amp;nbsp; &lt;BR /&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PIX-525, 256 MB RAM, CPU Pentium III 600 MHz&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Flash E28F128J3 @ 0xfff00000, 16MB&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BIOS Flash AM29F400B @ 0xfffd8000, 32KB&lt;BR /&gt;&lt;BR /&gt;Timeouts : &lt;BR /&gt;&lt;SPAN class="yiv999507258"&gt;&lt;STRONG&gt;&lt;SPAN class="yiv999507258"&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout xlate 3:00:00&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout uauth 0:05:00 absolute&lt;BR /&gt;&lt;SPAN class="yiv999507258"&gt;&lt;STRONG&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;&lt;SPAN class="yiv999507258"&gt;&lt;STRONG&gt;&lt;SPAN class="yiv999507258"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cisco PIX Security Appliance Software Version 7.0(2)&amp;nbsp; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;Firewall mode: Router&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258" style="font-size: 8pt;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Configuration Details : &lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;1) PIX’s Eth0 and Gi0/0 are set to :&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;Permit IP any any (Inbound / Outbound)&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;Permit ICMP any any (Inbound / Outbound)&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;2) Default route is set towards 172.16.21.1&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;SPAN class="yiv999507258"&gt; &lt;/SPAN&gt;3) NAT :&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;10.177.182.0 /24 &amp;gt;&amp;gt;&amp;gt;&amp;gt; PAT&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 172.16.21.1&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;---------NAT seems to be working fine because LAN users can ping the ISP Gateway of 172.16.21.1--------&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;BR /&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;STRONG&gt;&lt;SPAN class="yiv999507258" style="font-size: 14pt;"&gt;Problem:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;BR /&gt;LAN users fail to open Web pages with high graphic content.&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal" id="aui-3-2-0-114017"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;Example:&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Google.com can be opened from LAN, but yahoo.com is “stuck in loading” after loading some text content. Also some other Web-Sites with High Graphical content are also “stuck in loading”&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;....But if we run a bit torrent application we get good download speeds. Problems only comes while accessing certain web pages.&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;BR /&gt;... Again If NAT is not working ..... Nothing would open.. be it Google.com or Torrent&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;&lt;BR /&gt;&lt;SPAN class="yiv999507258" style="font-size: 14pt;"&gt;&lt;STRONG&gt;Trouble-Shooting : &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;To see whether the issue is with ISP, I connected a PC Directly to ISP’s Link and Assigned IP 172.16.21.34 and gateway 172.16.21.and DNS 172.16.0.1. Everything seems to be working fine. So its not an ISP issue and the Issue is with the Firewall.&lt;BR /&gt;&lt;BR /&gt;If I replace the firewall with a Router (Cisco 1841) and configure the Router to work in place of PIX then NAT works perfectly. &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt; &lt;/DIV&gt;&lt;DIV class="yiv999507258MsoNormal"&gt;So I beleive that the Problem is with PIX, But i cant figure out where&lt;BR /&gt; &lt;/DIV&gt;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN class="yiv999507258" style="color: #2d2d2d;"&gt;&lt;SPAN class="yiv999507258" style="font-family: 'bookman old style', 'new york', times, serif;"&gt;&lt;DIV style="font-weight: 800;"&gt;Pls Help...... Any Sggesstions are highly Welcome , Thanks in Advance&lt;/DIV&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV id="dock"&gt; &lt;/DIV&gt;&lt;DIV id="conv_dual_container"&gt; &lt;/DIV&gt;&lt;DIV id="slot_RS"&gt;&lt;DIV id="RS"&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV id="slot_RS2"&gt;&lt;DIV id="RS2"&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;IMG height="1" src="http://ad.yieldmanager.com/pixel?id=709459&amp;amp;t=2" width="1" /&gt; &lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654500#M568527</guid>
      <dc:creator>siddhartha_sarma</dc:creator>
      <dc:date>2019-03-11T19:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Nat Problem.. Need Ur Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654501#M568528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Siddharth,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Pls. refer this link: &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-8982"&gt;https://supportforums.cisco.com/docs/DOC-8982&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove http inspection if enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; .&lt;/P&gt;&lt;P&gt;&amp;nbsp; .&lt;BR /&gt;&amp;nbsp; inspect http&amp;nbsp; -----------------------&amp;gt; remove this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Jan 2011 13:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654501#M568528</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-29T13:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Nat Problem.. Need Ur Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654502#M568529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Madam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Http Inspection was disabled already, I even removed&amp;nbsp; Service Policy totally.. but the problem still persists. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also capture some packets from both the inside and the outside interfaces.. there was no "Oversized MSS"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2011 17:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654502#M568529</guid>
      <dc:creator>siddhartha_sarma</dc:creator>
      <dc:date>2011-02-02T17:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Nat Problem.. Need Ur Help</title>
      <link>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654503#M568530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Madam, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got the logs from pix, traffic captured on the outside interface&lt;/P&gt;&lt;P&gt;This is when the firewall is bypassed : Client IP 10.177.182.130, Server IP 180.151.249.174, notice that the pix is allowing the traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:38|302014: Teardown TCP connection 1390030 for outside:&lt;STRONG&gt;180.151.249.174/80&lt;/STRONG&gt; to LAN_ZONE:10.177.182.130/1176 duration 0:00:27 bytes 289053 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:38|302014: Teardown TCP connection 1390032 for outside:180.151.249.174/80 to LAN_ZONE:10.177.182.130/1178 duration 0:00:27 bytes 18077 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:38|302014: Teardown TCP connection 1390037 for outside:180.151.249.174/80 to LAN_ZONE:10.177.182.130/1179 duration 0:00:24 bytes 769 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:38|302014: Teardown TCP connection 1390028 for outside:180.151.249.174/80 to LAN_ZONE:10.177.182.130/1174 duration 0:00:27 bytes 38800 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:38|302014: Teardown TCP connection 1390031 for outside:180.151.249.174/80 to LAN_ZONE:10.177.182.130/1177 duration 0:00:27 bytes 6582 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:38|302014: Teardown TCP connection 1390029 for outside:180.151.249.174/80 to LAN_ZONE:10.177.182.130/1175 duration 0:00:27 bytes 77719 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:38|302014: Teardown TCP connection 1389139 for outside:209.85.153.154/80 to LAN_ZONE:10.177.182.130/1151 duration 0:04:10 bytes 7883 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:38|302014: Teardown TCP connection 1389140 for outside:209.85.153.154/80 to LAN_ZONE:10.177.182.130/1152 duration 0:04:10 bytes 7296 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:28|302014: Teardown TCP connection 1389026 for outside:209.85.175.102/80 to LAN_ZONE:10.177.182.130/1131 duration 0:04:27 bytes 68873 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:28|302014: Teardown TCP connection 1389019 for outside:209.85.175.102/80 to LAN_ZONE:10.177.182.130/1127 duration 0:04:28 bytes 145609 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:28|302014: Teardown TCP connection 1389025 for outside:209.85.153.154/80 to LAN_ZONE:10.177.182.130/1130 duration 0:04:27 bytes 7427 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:13|302013: Built outbound TCP connection 1390037 for outside:180.151.249.174/80 (180.151.249.174/80) toLAN_ZONE:10.177.182.130/1179(10.177.182.130/1179)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:10|302013: Built outbound TCP connection 1390032 for outside:180.151.249.174/80 (180.151.249.174/80) to LAN_ZONE:10.177.182.130/1178(10.177.182.130/1178)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:10|302013: Built outbound TCP connection 1390031 for outside:180.151.249.174/80 (180.151.249.174/80) to LAN_ZONE:10.177.182.130/1177(10.177.182.130/1177)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:10|302013: Built outbound TCP connection 1390030 for outside:180.151.249.174/80 (180.151.249.174/80) to LAN_ZONE:10.177.182.130/1176(10.177.182.130/1176)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:10|302013: Built outbound TCP connection 1390029 for outside:180.151.249.174/80 (180.151.249.174/80) to LAN_ZONE:10.177.182.130/1175(10.177.182.130/1175)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:10|302014: Teardown TCP connection 1390027 for outside:180.151.249.174/80 to LAN_ZONE:10.177.182.130/1173 duration 0:00:00 bytes 1406 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:10|302013: Built outbound TCP connection 1390028 for outside:180.151.249.174/80 (180.151.249.174/80) to LAN_ZONE:10.177.182.130/1174(10.177.182.130/1174)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:10|302013: Built outbound TCP connection 1390027 for outside:180.151.249.174/80 (180.151.249.174/80) to LAN_ZONE:10.177.182.130/1173(10.177.182.130/1173)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1389035 for outside:74.125.95.113/80 to LAN_ZONE:10.177.182.130/1138 duration 0:04:05 bytes 1194 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1388835 for outside:80.150.142.17/80 to LAN_ZONE:10.177.182.130/1109 duration 0:05:04 bytes 9197 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1389030 for outside:209.85.175.102/80 to LAN_ZONE:10.177.182.130/1135 duration 0:04:07 bytes 2307 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1389028 for outside:209.85.175.100/80 to LAN_ZONE:10.177.182.130/1133 duration 0:04:07 bytes 5345 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1389023 for outside:209.85.175.100/80 to LAN_ZONE:10.177.182.130/1129 duration 0:04:07 bytes 5009 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1389020 for outside:209.85.175.102/80 to LAN_ZONE:10.177.182.130/1128 duration 0:04:08 bytes 50638 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1389031 for outside:209.85.175.102/80 to LAN_ZONE:10.177.182.130/1136 duration 0:04:07 bytes 51902 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1389029 for outside:209.85.175.102/80 to LAN_ZONE:10.177.182.130/1134 duration 0:04:07 bytes 4319 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:08|302014: Teardown TCP connection 1389027 for outside:209.85.175.100/80 to LAN_ZONE:10.177.182.130/1132 duration 0:04:07 bytes 4644 TCP FINs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:04|302013: Built outbound TCP connection 1390014 for outside:209.85.175.101/80 (209.85.175.101/80) to LAN_ZONE:10.177.182.130/1172 (10.177.182.130/1172)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:04|302016: Teardown UDP connection 1390013 for outside:172.16.0.1/53 to LAN_ZONE:10.177.182.130/55470 duration 0:00:00 bytes 344&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:04|302015: Built outbound UDP connection 1390013 for outside:172.16.0.1/53 (172.16.0.1/53) to LAN_ZONE:10.177.182.130/55470 (10.177.182.130/55470)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:04|302016: Teardown UDP connection 1390012 for outside:172.16.0.1/53 to LAN_ZONE:10.177.182.130/59078 duration 0:00:00 bytes 155&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:11:04|302015: Built outbound UDP connection 1390012 for outside:172.16.0.1/53 (172.16.0.1/53) to LAN_ZONE:10.177.182.130/59078 (10.177.182.130/59078)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is when the traffic is passed through the firewall : no thice that the pix is dropping the&amp;nbsp; traffic , reason : &lt;SPAN&gt;IP options: "Stream ID&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:27|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:26|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:22|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:22|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:22|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:22|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387926 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1061 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387925 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1060 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387923 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1058 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387924 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1059 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387930 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1065 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387927 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1062 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387929 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1064 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387922 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1057 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387919 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1055 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387920 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1056 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387918 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1054 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:18|302014: Teardown TCP connection 1387928 for outside:202.86.6.175/80 to LAN_ZONE:10.177.182.130/1063 duration 0:01:05 bytes 0 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:11|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:04:03|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:58|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:58|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:58|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:58|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:57|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:53|302014: Teardown TCP connection 1382520 for LAN_ZONE:10.177.182.130/4804 to NP Identity Ifc:10.177.182.1/23 duration 0:17:29 bytes 21329 TCP FINs&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:50|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:48|106012: Deny IP from 202.86.6.175 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:46|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:46|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:46|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:46|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:43|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:41|106012: Deny IP from 203.84.220.39 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:40|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:40|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:40|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:40|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:40|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:38|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:37|106012: Deny IP from 180.151.249.174 to 10.177.182.130, IP options: "Stream ID"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:36|302013: Built outbound TCP connection 1388081 for outside:180.151.249.174/80 &lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;0.1/53) to LAN_ZONE:10.177.182.130/50209 (10.177.182.130/50209)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN style="font-size: 8pt;"&gt;6|Apr 07 2011 17:03:28|302015: Built outbound UDP connection 1388049 for outside:172.16.0.1/53 (172.16.0.1/53) to LAN_ZONE:10.177.182.130/56402 (10.177.182.130/56402)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;However&amp;nbsp; Only Http traffic is being denied, all other traffic eg Torrent etc is allowed without any problem.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;The ISP says its not its problem as the traffic is dropped only when passed through the firewall&lt;/DIV&gt;&lt;DIV&gt;Also, the ISP is passign the traffic through a Squid proxy. &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Could you kindly suggest any solution to this problem&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Apr 2011 08:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-nat-problem-need-ur-help/m-p/1654503#M568530</guid>
      <dc:creator>siddhartha_sarma</dc:creator>
      <dc:date>2011-04-29T08:01:33Z</dc:date>
    </item>
  </channel>
</rss>

