<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Deny TCP Reverse Path Check in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deny-tcp-reverse-path-check/m-p/824634#M84928</link>
    <description>&lt;P&gt;I have a pix 506E and I get ~ 20 /sec of the these messages. The message is Deny tcp src outside:xxx.xxx.xxx.xxx/29977 dst inside:yyy.yyy.yyy.yyy/25 by access-group "OUTSIDE_ACCESS_IN" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where yyy.yyy.yyy.yyy is my webserver.  I realize that this means its being blocked, but its becoming a DoS due to the high number.  They are comming from many different external IP addresses&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:56:20 GMT</pubDate>
    <dc:creator>chris unger</dc:creator>
    <dc:date>2019-03-10T10:56:20Z</dc:date>
    <item>
      <title>Deny TCP Reverse Path Check</title>
      <link>https://community.cisco.com/t5/network-security/deny-tcp-reverse-path-check/m-p/824634#M84928</link>
      <description>&lt;P&gt;I have a pix 506E and I get ~ 20 /sec of the these messages. The message is Deny tcp src outside:xxx.xxx.xxx.xxx/29977 dst inside:yyy.yyy.yyy.yyy/25 by access-group "OUTSIDE_ACCESS_IN" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where yyy.yyy.yyy.yyy is my webserver.  I realize that this means its being blocked, but its becoming a DoS due to the high number.  They are comming from many different external IP addresses&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-tcp-reverse-path-check/m-p/824634#M84928</guid>
      <dc:creator>chris unger</dc:creator>
      <dc:date>2019-03-10T10:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Deny TCP Reverse Path Check</title>
      <link>https://community.cisco.com/t5/network-security/deny-tcp-reverse-path-check/m-p/824635#M84929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syslog message 106023 simply indicates that the firewall has denied a packet based on the src/dest in the syslog itself.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would be asking is why are so many different external servers trying to send email (TCP/25) to my web server?  Is your web server an email server as well?  Is your web server listed with an MX entry in DNS for your domain?  If so, why are you not allowing other mail servers to send email to it?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2008 05:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-tcp-reverse-path-check/m-p/824635#M84929</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2008-01-14T05:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Deny TCP Reverse Path Check</title>
      <link>https://community.cisco.com/t5/network-security/deny-tcp-reverse-path-check/m-p/824636#M84930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My web server is not an email server, our external DNS MX record doesn't point to the webserver.  The only traffic allowed by my ACL is port 80.&lt;/P&gt;&lt;P&gt;I feel that we are being attacked, and I have tried tracing the Ip addresses and report them but so far I haven't succeced with any.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2008 17:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-tcp-reverse-path-check/m-p/824636#M84930</guid>
      <dc:creator>chris unger</dc:creator>
      <dc:date>2008-01-14T17:10:32Z</dc:date>
    </item>
  </channel>
</rss>

