<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Blocking remote site in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291354#M777576</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Andrew for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you elaborate more on how a loop or suboptimal route could cause the ASA to drop traffic? The problematic site is connected to the main site via single p2p serial link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Dec 2009 18:52:14 GMT</pubDate>
    <dc:creator>mo shea</dc:creator>
    <dc:date>2009-12-02T18:52:14Z</dc:date>
    <item>
      <title>ASA Blocking remote site</title>
      <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291352#M777574</link>
      <description>&lt;P&gt;Hi...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the following setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Data Center--&amp;gt; 2 6506 Switches (vss)--&amp;gt; 2 ASAs (Active/Standby) Outside--&amp;gt; 7206 Router connecting several E1 (G.703) sites&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OSPF is running on 6506, ASA, and routers.&lt;/P&gt;&lt;P&gt;ASA is running 7.0 code, no nat is configured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our remote sites connected via a 2mb E1 G.703 link was being denied by the asa, with many messages like the one below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%asa-2-106001: Inbound tcp connection denied from "DataCenter server ip"/80 to "Remote site ip"/1535 flags syn ack on interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was also getting many messages like - UDP denied due to DNS reply. This site has been running fine for 2 months before this incident.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to telnet from my pc (asa inside segment) to the remote site router, but couldnt get any further. None of the remote site users were able to access the dat center resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem was resolved when I shut down the serial interface on the 7206 router connecting to that site and no shut it again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I do not suspect any syn attack since the connection was fine after the interface was reset.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be asymmetric routing, Although this is a point to point link?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can our SP cause asymetric routing? To be more specific can asymetric routing occur due to layer 2 issues? The reason behind my question is that previously we faced a link problem with the same remote site and it was SP related, they had 2 active connections to the site although we have 1 E1 circuit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if there are any other reasons that I might have overlooked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All Help is appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:44:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291352#M777574</guid>
      <dc:creator>mo shea</dc:creator>
      <dc:date>2019-03-11T16:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Blocking remote site</title>
      <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291353#M777575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should check your router logs for OSPF routing changes to see if there was a loop/suboptimal route around the time this happend&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Dec 2009 14:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291353#M777575</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-12-02T14:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Blocking remote site</title>
      <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291354#M777576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Andrew for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you elaborate more on how a loop or suboptimal route could cause the ASA to drop traffic? The problematic site is connected to the main site via single p2p serial link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Dec 2009 18:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291354#M777576</guid>
      <dc:creator>mo shea</dc:creator>
      <dc:date>2009-12-02T18:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Blocking remote site</title>
      <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291355#M777577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your original post you posted:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"%asa-2-106001: Inbound tcp connection denied from "DataCenter server ip"/80 to "Remote site ip"/1535 flags syn ack on interface outside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have an acl on the outside of the ASA in the oubound direction?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 10:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291355#M777577</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-12-03T10:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Blocking remote site</title>
      <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291356#M777578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not have any acls on the outbound direction. There is only one acl on the outside in the inbound direction. It feels strange that the ASA was blocking outbound traffic and to this site only, since other remote sites were accessing the DC freely.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I still wonder whether SP layer 2 issues can cause asymmetric routing that makes ASA to act this way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 20:10:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291356#M777578</guid>
      <dc:creator>mo shea</dc:creator>
      <dc:date>2009-12-03T20:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Blocking remote site</title>
      <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291357#M777579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It all has to do with the log entry - again I post it:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"%asa-2-106001: Inbound tcp connection denied from "DataCenter server ip"/80 to "Remote site ip"/1535 flags syn ack on interface outside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to your diagram - below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Data Center--&amp;gt; 2 6506 Switches (vss)--&amp;gt; 2 ASAs (Active/Standby) Outside--&amp;gt; 7206 Router connecting several E1 (G.703) sites&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why would the ASA recevie a frame on the outside interface with a source IP of a data center device trying to get to a remote end device connected to another interface on the ASA?&amp;nbsp; Unless the 7206 had a route/routes that indicated the next hop for the remote site was the ASA, or there is a posssible another physical loop between the 6506 and the 7206.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again - check your routing logs at the time of the incident, to see if there is any other indication of a possible issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Dec 2009 11:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291357#M777579</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-12-04T11:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Blocking remote site</title>
      <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291358#M777580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Andrew for the explanation. It never hit me until you pointed out the log entry,&amp;nbsp; twice &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;. I will check it out in Monday.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rds.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Dec 2009 12:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291358#M777580</guid>
      <dc:creator>mo shea</dc:creator>
      <dc:date>2009-12-05T12:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Blocking remote site</title>
      <link>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291359#M777581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - it's all good.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Dec 2009 13:30:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-blocking-remote-site/m-p/1291359#M777581</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-12-05T13:30:56Z</dc:date>
    </item>
  </channel>
</rss>

