<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX building connections on wrong interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557230#M705383</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post the output of "show static" from the PIX. Also, please apply captures on the testlan interface and check if you actually see packets going out on that interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1222"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Nov 2010 15:57:12 GMT</pubDate>
    <dc:creator>praprama</dc:creator>
    <dc:date>2010-11-10T15:57:12Z</dc:date>
    <item>
      <title>PIX building connections on wrong interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557229#M705381</link>
      <description>&lt;P&gt;I have a PIX-515 which is building connections between 2 host in the same subnet (172.16.8.0 /21), the PIX interface to this network is named 'inside' and has an IP of 172.16.8.254 /21. The pix also has a connection to a test network (172.30.8.0 /21), the pix interface for this network is named 'testlan' and has an IP of 172.30.8.250 /21. The problem is that the logs are showing a connection being built from 'inside' to 'testlan' for communications between hosts on the 172.16.8.0 /21 network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I hitting a bug? The two host reside in the same network on the 'inside' interface but the connections are built to the 'testlan' interface on a different subnet!!. I believe this may be an issue with the logs being wrong as the services are up and running and none of the hosts reside in 'testlan'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;LOGS:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 28 22:34:49 Oct 28 2031 21:35:32 TESTPIX : %PIX-6-302015: Built outbound UDP connection 43661517 for testlan:172.16.15.246/5394 (172.16.15.246/5394) to inside:172.16.15.32/389 (172.16.15.32/389)&lt;BR /&gt;Oct 28 22:37:00 Oct 28 2031 21:37:43 TESTPIX : %PIX-6-302016: Teardown UDP connection 43661517 for testlan:172.16.15.246/5394 to inside:172.16.15.32/389 duration 0:02:11 bytes 504&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 28 22:38:31 Oct 28 2031 21:39:14 TESTPIX : %PIX-6-302015: Built outbound UDP connection 43671234 for testlan:172.16.9.15/137 (172.16.9.15/137) to inside:172.16.15.32/137 (172.16.15.32/137)&lt;BR /&gt;Oct 28 22:40:32 Oct 28 2031 21:41:15 TESTPIX : %PIX-6-302016: Teardown UDP connection 43671234 for testlan:172.16.9.15/137 to inside:172.16.15.32/137 duration 0:02:01 bytes 76&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 28 09:23:43 Oct 28 2031 08:24:26 TESTPIX : %PIX-6-302013: Built outbound TCP connection 41013159 for testlan:172.16.15.32/1026 (172.16.15.32/1026) to inside:172.16.15.31/4297 (172.16.15.31/4297)&lt;BR /&gt;Oct 28 09:25:44 Oct 28 2031 08:26:27 TESTPIX : %PIX-6-302014: Teardown TCP connection 41013159 for testlan:172.16.15.32/1026 to inside:172.16.15.31/4297 duration 0:02:01 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 28 09:29:20 Oct 28 2031 08:30:03 TESTPIX : %PIX-6-302015: Built outbound UDP connection 41026172 for testlan:172.16.15.32/137 (172.16.15.32/137) to inside:192.168.0.100/137 (172.30.8.250/337)&lt;BR /&gt;Oct 28 09:32:01 Oct 28 2031 08:32:44 TESTPIX : %PIX-6-302016: Teardown UDP connection 41026172 for testlan:172.16.15.32/137 to inside:192.168.0.100/137 duration 0:02:41 bytes 2070&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cisco PIX Firewall Version 6.3(4)&lt;BR /&gt;Cisco PIX Device Manager Version 3.0(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Fri 02-Jul-04 00:07 by morlee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TESTPIX up 126 days 4 hours&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp; PIX-515, 64 MB RAM, CPU Pentium 200 MHz&lt;BR /&gt;Flash i28F640J5 @ 0x300, 16MB&lt;BR /&gt;BIOS Flash AT29C257 @ 0xfffd8000, 32KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0: ethernet0: address is 0003.6bf7.4e20, irq 11&lt;BR /&gt;1: ethernet1: address is 0003.6bf7.4e21, irq 10&lt;BR /&gt;2: ethernet2: address is 00e0.b601.d185, irq 9&lt;BR /&gt;3: ethernet3: address is 00e0.b601.d184, irq 9&lt;BR /&gt;4: ethernet4: address is 00e0.b601.d183, irq 9&lt;BR /&gt;5: ethernet5: address is 00e0.b601.d182, irq 9&lt;BR /&gt;Licensed Features:&lt;BR /&gt;Failover:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;BR /&gt;VPN-DES:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;BR /&gt;VPN-3DES-AES:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;BR /&gt;Maximum Physical Interfaces: 6&lt;BR /&gt;Maximum Interfaces:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&lt;BR /&gt;Cut-through Proxy:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;BR /&gt;Guards:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;BR /&gt;URL-filtering:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&lt;BR /&gt;Inside Hosts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unlimited&lt;BR /&gt;Throughput:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unlimited&lt;BR /&gt;IKE peers:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This PIX has an Unrestricted (UR) license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: 406042612 (0x1833b7f4)&lt;BR /&gt;Running Activation Key: 0xb8a9f990 0xc0d952fd 0x2a2de635 0x729a7248&lt;BR /&gt;Configuration last modified by enable_1 at 12:02:46.599 GMT/BST Mon Nov 10 2031&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;nat (inside) 0 access-list acl_nonat_traffic&lt;BR /&gt;nat (inside) 1 172.16.0.0 255.255.248.0 0 0&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (testlan) 1 interface&lt;BR /&gt;global (testlan) 1 172.30.8.245&lt;BR /&gt;global (testlan) 1 172.30.8.246&lt;BR /&gt;global (testlan) 1 172.30.8.247&lt;BR /&gt;global (testlan) 1 172.30.8.248&lt;BR /&gt;global (testlan) 1 172.30.8.249&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;BR /&gt;nameif ethernet1 inside security100&lt;BR /&gt;nameif ethernet2 testlan security90&lt;BR /&gt;nameif ethernet3 WebDMZ security50&lt;BR /&gt;nameif ethernet4 EPOS security40&lt;BR /&gt;nameif ethernet5 externaldmz security10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_outside in interface outside&lt;BR /&gt;access-group testlan in interface testlan&lt;BR /&gt;access-group acl_WebDMZ in interface WebDMZ&lt;BR /&gt;access-group acl_EPOS in interface EPOS&lt;BR /&gt;access-group acl_externaldmz in interface externaldmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;testlan 172.30.8.0 255.255.248.0 172.30.8.250 1 CONNECT static&lt;BR /&gt;inside 172.16.8.0 255.255.248.0 172.16.8.254 1 CONNECT static&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System IP Addresses:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address outside totevpn 255.255.255.248&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address inside 172.16.8.254 255.255.248.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address testlan 172.30.8.250 255.255.248.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address WebDMZ 172.30.240.250 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address EPOS 172.20.1.246 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address externaldmz 192.168.20.250 255.255.255.0&lt;BR /&gt;Current IP Addresses:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address outside totevpn 255.255.255.248&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address inside 172.16.8.254 255.255.248.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address testlan 172.30.8.250 255.255.248.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address WebDMZ 172.30.240.250 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address EPOS 172.20.1.246 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address externaldmz 192.168.20.250 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,testlan) 172.16.15.40 172.16.15.40 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.16.8.40 172.16.8.40 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.16.8.30 172.16.8.30 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.16.8.50 172.16.8.50 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.16.15.2 172.16.15.2 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.16.8.33 172.16.8.33 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.16.15.5 172.16.15.5 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) Live_PostCode Live_PostCode netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.16.8.0 172.16.8.0 netmask 255.255.248.0 0 0&lt;BR /&gt;static (inside,testlan) BCSDC1 BCSDC1 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) BCSTXCLUSTER BCSTXCLUSTER netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.25.15.111 172.25.15.111 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.25.8.0 172.25.8.0 netmask 255.255.248.0 0 0&lt;BR /&gt;static (inside,testlan) 10.224.32.0 10.224.32.0 netmask 255.255.255.0 0 0&lt;BR /&gt;static (inside,testlan) 172.16.15.140 172.16.15.140 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 192.168.50.40 192.168.50.40 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 192.168.50.30 192.168.50.30 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 172.16.10.78 172.16.10.78 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) DevServerNew DevServerNew netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) TOGSMA01 TOGSMA01 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 192.168.112.9 192.168.112.9 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 192.168.112.10 192.168.112.10 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 192.168.112.0 192.168.112.0 netmask 255.255.254.0 0 0&lt;BR /&gt;static (inside,testlan) 172.30.8.32 172.30.8.32 netmask 255.255.255.255 0 0&lt;BR /&gt;static (inside,testlan) 10.4.0.0 10.4.0.0 netmask 255.255.0.0 0 0&lt;BR /&gt;static (inside,testlan) 10.8.56.0 10.8.56.0 netmask 255.255.255.0 0 0&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557229#M705381</guid>
      <dc:creator>bluesteel</dc:creator>
      <dc:date>2019-03-11T19:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX building connections on wrong interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557230#M705383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post the output of "show static" from the PIX. Also, please apply captures on the testlan interface and check if you actually see packets going out on that interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1222"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 15:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557230#M705383</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-11-10T15:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: PIX building connections on wrong interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557231#M705385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prapanch,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I ran packet capture and no packets captured exiting the testlan interface. I think I'm hitting a bug as I can see in the logs that the pix is moving the host from LAN to LAN????? As you can see 172.16.15.32 is on inside: in the first log entry but moves to testlan: in the second log entry...WRONG!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Oct 28 22:34:49 Oct 28 2031 21:35:32 TESTPIX : %PIX-6-302015: Built outbound UDP connection 43661517 for testlan:172.16.15.246/5394 (172.16.15.246/5394) to inside:172.16.15.32/389 (172.16.15.32/389)&lt;BR /&gt;Oct 28 22:37:00 Oct 28 2031 21:37:43 TESTPIX : %PIX-6-302016: Teardown UDP connection 43661517 for testlan:172.16.15.246/5394 to inside:172.16.15.32/389 duration 0:02:11 bytes 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 28 09:23:43 Oct 28 2031 08:24:26 TESTPIX : %PIX-6-302013: Built outbound TCP connection 41013159 for testlan:172.16.15.32/1026 (172.16.15.32/1026) to inside:172.16.15.31/4297 (172.16.15.31/4297)&lt;BR /&gt;Oct 28 09:25:44 Oct 28 2031 08:26:27 TESTPIX : %PIX-6-302014: Teardown TCP connection 41013159 for testlan:172.16.15.32/1026 to inside:172.16.15.31/4297 duration 0:02:01 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 13:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557231#M705385</guid>
      <dc:creator>bluesteel</dc:creator>
      <dc:date>2010-11-11T13:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX building connections on wrong interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557232#M705387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's weird that you do not see any apckets captured!! Could you post the capture configuration here just for confirmation? Also, try adding the command"ip verify reverse-path interface testlan" and "ip verify reverse-path interface inside" and see if the logs stop popping up then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 14:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557232#M705387</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-11-11T14:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX building connections on wrong interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557233#M705388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prapanch,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I did see traffic hitting the inside interface (in-cap) but none exiting the testlan interface (out-cap).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 17:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557233#M705388</guid>
      <dc:creator>bluesteel</dc:creator>
      <dc:date>2010-11-11T17:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: PIX building connections on wrong interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557234#M705389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prapanch,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; the packet capture config, note access-list does not need mirroring !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cap-list permit tcp 172.16.8.0 255.255.248.0 172.16.8.0 255.255.248.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture in-cap interface inside access-list cap-list buffer 1000000 packet 1522&lt;BR /&gt;capture out-cap interface testlan access-list cap-list buffer 1000000 packet 1522&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 17:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557234#M705389</guid>
      <dc:creator>bluesteel</dc:creator>
      <dc:date>2010-11-11T17:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: PIX building connections on wrong interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557235#M705392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The captures seem alright. Did you try adding that command i mentioned and see if it helped? I owuld suggest opening up a TAC case to investigate further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 15:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-building-connections-on-wrong-interface/m-p/1557235#M705392</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-11-12T15:26:35Z</dc:date>
    </item>
  </channel>
</rss>

