<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog message about inside interface of PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syslog-message-about-inside-interface-of-pix/m-p/59485#M688271</link>
    <description>&lt;P&gt;After upgraded from v5.3 to v6.0, I found the following log messages:&lt;/P&gt;&lt;P&gt;&amp;lt;166&amp;gt;Sep 14 2001 15:35:45: %PIX-6-106015: Deny TCP (no connection) from 192.168.140.63/139 to 192.168.140.61/1507 flags PSH ACK  on interface inside&lt;/P&gt;&lt;P&gt;&amp;lt;166&amp;gt;Sep 14 2001 15:35:48: %PIX-6-106015: Deny TCP (no connection) from 192.168.140.63/139 to 192.168.140.61/1507 flags RST  on interface inside&lt;/P&gt;&lt;P&gt;&amp;lt;166&amp;gt;Sep 14 2001 15:35:54: %PIX-6-106015: Deny TCP (no connection) from 192.168.140.63/139 to 192.168.140.61/1507 flags RST  on interface inside&lt;/P&gt;&lt;P&gt;&amp;lt;166&amp;gt;Sep 14 2001 15:36:13: %PIX-6-302005: Built UDP connection for faddr 203.194.171.227/137 gaddr 203.194.171.243/137 laddr 192.168.140.243/137&lt;/P&gt;&lt;P&gt;Please note that the inside address of 192.168.140.61 maps to 203.194.171.227 and 192.168.140.243 maps to 203.194.171.243.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is difficult for myself to explain why inside traffic is blocked or making connection on outside instead of inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone can help to explain this?  Or help to fix the problem?&lt;/P&gt;&lt;P&gt;Many Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 05:49:46 GMT</pubDate>
    <dc:creator>j.joe</dc:creator>
    <dc:date>2020-02-21T05:49:46Z</dc:date>
    <item>
      <title>Syslog message about inside interface of PIX</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-about-inside-interface-of-pix/m-p/59485#M688271</link>
      <description>&lt;P&gt;After upgraded from v5.3 to v6.0, I found the following log messages:&lt;/P&gt;&lt;P&gt;&amp;lt;166&amp;gt;Sep 14 2001 15:35:45: %PIX-6-106015: Deny TCP (no connection) from 192.168.140.63/139 to 192.168.140.61/1507 flags PSH ACK  on interface inside&lt;/P&gt;&lt;P&gt;&amp;lt;166&amp;gt;Sep 14 2001 15:35:48: %PIX-6-106015: Deny TCP (no connection) from 192.168.140.63/139 to 192.168.140.61/1507 flags RST  on interface inside&lt;/P&gt;&lt;P&gt;&amp;lt;166&amp;gt;Sep 14 2001 15:35:54: %PIX-6-106015: Deny TCP (no connection) from 192.168.140.63/139 to 192.168.140.61/1507 flags RST  on interface inside&lt;/P&gt;&lt;P&gt;&amp;lt;166&amp;gt;Sep 14 2001 15:36:13: %PIX-6-302005: Built UDP connection for faddr 203.194.171.227/137 gaddr 203.194.171.243/137 laddr 192.168.140.243/137&lt;/P&gt;&lt;P&gt;Please note that the inside address of 192.168.140.61 maps to 203.194.171.227 and 192.168.140.243 maps to 203.194.171.243.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is difficult for myself to explain why inside traffic is blocked or making connection on outside instead of inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone can help to explain this?  Or help to fix the problem?&lt;/P&gt;&lt;P&gt;Many Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:49:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-about-inside-interface-of-pix/m-p/59485#M688271</guid>
      <dc:creator>j.joe</dc:creator>
      <dc:date>2020-02-21T05:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog message about inside interface of PIX</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-about-inside-interface-of-pix/m-p/59486#M688272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Deny TCP (no connection) simply means the PIX has not built a valid state to allow this TCP connection.  It needs to see a SYN and a SYN ACK to allow the TCP connection).  If this happened immediately after your upgrade, there may have been a state established prior that was lost during the upgrade.   If it&amp;#146;s still happening regularly, it&amp;#146;s either a bug in 6.0 (I couldn&amp;#146;t find one using bug tracker) or maybe shutting down the PIX will for a few minutes will force these windows box&amp;#146;s (139 TCP is NetBios) to realize the connection has terminated.  The destination machine isn&amp;#146;t even getting the RST but should reset itself after a few minutes anyway.    Finally, try holding the connection state open longer with the &amp;#147;sysopt connection timewait&amp;#148; command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2001 19:18:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-about-inside-interface-of-pix/m-p/59486#M688272</guid>
      <dc:creator>bstremp</dc:creator>
      <dc:date>2001-09-20T19:18:10Z</dc:date>
    </item>
  </channel>
</rss>

