<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firewall connection log in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-connection-log/m-p/1274330#M824547</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The capture shows the client (202.94.66.21) sending a TCP SYN, followed by 46.56.76.34 sending a TCP RST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means that either the NAT is not configured properly, or the access-list is not permitting the inbound traffic, or the traffic goes through but the server is not listening to port 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the syslogs, check the same capture on the inside interface, check if you can connect to the server (on its private ip addess) from a client on the inside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Nov 2009 09:00:12 GMT</pubDate>
    <dc:creator>Herbert Baerten</dc:creator>
    <dc:date>2009-11-09T09:00:12Z</dc:date>
    <item>
      <title>firewall connection log</title>
      <link>https://community.cisco.com/t5/network-security/firewall-connection-log/m-p/1274329#M824524</link>
      <description>&lt;P&gt;WOuld need advise on the attached logs from a connection , obtained by tcpdump on a firewall.&lt;/P&gt;&lt;P&gt;46.56.76.34 is the global ip of ours which is been NAT on the device. the private ip for this hosts a website, which is inaccessible.&lt;/P&gt;&lt;P&gt;202.94.66.21 is the internet ip used to check if the site is reachable.&lt;/P&gt;&lt;P&gt;Please suggest what does these logs indicate.&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-connection-log/m-p/1274329#M824524</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T16:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: firewall connection log</title>
      <link>https://community.cisco.com/t5/network-security/firewall-connection-log/m-p/1274330#M824547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The capture shows the client (202.94.66.21) sending a TCP SYN, followed by 46.56.76.34 sending a TCP RST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This means that either the NAT is not configured properly, or the access-list is not permitting the inbound traffic, or the traffic goes through but the server is not listening to port 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the syslogs, check the same capture on the inside interface, check if you can connect to the server (on its private ip addess) from a client on the inside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 09:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-connection-log/m-p/1274330#M824547</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2009-11-09T09:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: firewall connection log</title>
      <link>https://community.cisco.com/t5/network-security/firewall-connection-log/m-p/1274331#M824553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The logs which are attached in the notepad give me a feeling,when connection is intiated from 202.94.66.21 to 46.56.76.34 on port 443 the server which is 46.56.76.34 is replying with a RST packet.so this could be the server is not listening on port 443&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Nov 2009 14:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-connection-log/m-p/1274331#M824553</guid>
      <dc:creator>austin522</dc:creator>
      <dc:date>2009-11-10T14:14:48Z</dc:date>
    </item>
  </channel>
</rss>

