<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Weird PIX problem accessing a specific website in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/weird-pix-problem-accessing-a-specific-website/m-p/147176#M604806</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but it doesn't really explain why it works fine from every other network, including networks behind PIX's.  Why would it be answering from the wrong IP to only one site?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Jun 2003 10:15:12 GMT</pubDate>
    <dc:creator>fpineau</dc:creator>
    <dc:date>2003-06-11T10:15:12Z</dc:date>
    <item>
      <title>Weird PIX problem accessing a specific website</title>
      <link>https://community.cisco.com/t5/network-security/weird-pix-problem-accessing-a-specific-website/m-p/147174#M604804</link>
      <description>&lt;P&gt;I have a weird problem trying to access a specific website.  No client&lt;/P&gt;&lt;P&gt;inside the PIX can hit it (although they can all ping it).  Clients&lt;/P&gt;&lt;P&gt;outside the firewall (on different networks) are fine.  I get the&lt;/P&gt;&lt;P&gt;following messages on the firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;302001: Built outbound TCP connection 49750 for faddr &amp;lt;TARGET&lt;/P&gt;&lt;P&gt;SUBNET&amp;gt;.179/80 gaddr &amp;lt;SRC SUBNET&amp;gt;.174/3128 laddr 192.168.1.251/3128&lt;/P&gt;&lt;P&gt;106015: Deny TCP (no connection) from &amp;lt;TARGET SUBNET&amp;gt;.178/80 to &amp;lt;SRC&lt;/P&gt;&lt;P&gt;SUBNET&amp;gt;.174/3128 flags SYN ACK  on interface outside&lt;/P&gt;&lt;P&gt;106015: Deny TCP (no connection) from &amp;lt;TARGET SUBNET&amp;gt;.178/80 to &amp;lt;SRC&lt;/P&gt;&lt;P&gt;SUBNET&amp;gt;.174/3128 flags SYN ACK  on interface outside&lt;/P&gt;&lt;P&gt;106015: Deny TCP (no connection) from &amp;lt;TARGET SUBNET&amp;gt;.178/80 to &amp;lt;SRC&lt;/P&gt;&lt;P&gt;SUBNET&amp;gt;.174/3128 flags ACK  on interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;("&amp;lt;TARGET SUBNET&amp;gt;" and "&amp;lt;SRC SUBNET&amp;gt;" are my edits)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;SRC SUBNET&amp;gt;.174 is a static map to 192.168.1.251&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The errors seem to indicate that the syn ack is coming back from the&lt;/P&gt;&lt;P&gt;wrong IP address (.178), so the PIX disallows it as it is expecting it&lt;/P&gt;&lt;P&gt;from .179&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried this behind several other PIX's on different networks and&lt;/P&gt;&lt;P&gt;had no trouble.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming for the moment that the TARGET site made no changes, is there&lt;/P&gt;&lt;P&gt;anything on the SRC PIX that could account for this?  A bug in the FW&lt;/P&gt;&lt;P&gt;software, for example?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect the target site made some sort of change (they said they&lt;/P&gt;&lt;P&gt;didn't, but they always say that, don't they?) but I need to be able&lt;/P&gt;&lt;P&gt;to rule out everything on this end first.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-pix-problem-accessing-a-specific-website/m-p/147174#M604804</guid>
      <dc:creator>fpineau</dc:creator>
      <dc:date>2020-02-21T06:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Weird PIX problem accessing a specific website</title>
      <link>https://community.cisco.com/t5/network-security/weird-pix-problem-accessing-a-specific-website/m-p/147175#M604805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are to the point accurate with your analysis on the log.  It appears that the web server is sending a response back using a different ip which is .178 instead of .179.  So, pix is simply dropping the packets as there is no xlate/conn object .  I am confident that the problem is not with the PIX, and if really want to prove it, you proabably can put a sniffer on the outside of the pix to verify if pix is logging it right.  Based on the pix log, the problem is definitely with the webserver. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2003 04:17:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-pix-problem-accessing-a-specific-website/m-p/147175#M604805</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-06-11T04:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Weird PIX problem accessing a specific website</title>
      <link>https://community.cisco.com/t5/network-security/weird-pix-problem-accessing-a-specific-website/m-p/147176#M604806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but it doesn't really explain why it works fine from every other network, including networks behind PIX's.  Why would it be answering from the wrong IP to only one site?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2003 10:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-pix-problem-accessing-a-specific-website/m-p/147176#M604806</guid>
      <dc:creator>fpineau</dc:creator>
      <dc:date>2003-06-11T10:15:12Z</dc:date>
    </item>
  </channel>
</rss>

