<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA log - Deny tcp fin ack on int mgmt in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223977#M859730</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is exactly my point and I would view this as a deficiency.  The ASA should be able to properly terminate connections, especially from / to itself.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Let me know if you agree or disagree with the assessment.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Also, I opened a dialog on NetPro on this topic.  Would you be willing to post your respose there too?  At least one other person was seeking a resolution for this issue.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Mike Palmer&lt;/P&gt;&lt;P&gt;Bremer Financial.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 May 2009 19:19:25 GMT</pubDate>
    <dc:creator>mlpalmer</dc:creator>
    <dc:date>2009-05-22T19:19:25Z</dc:date>
    <item>
      <title>ASA log - Deny tcp fin ack on int mgmt</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223973#M859726</link>
      <description>&lt;P&gt;While in ASDM via the management interface, I get ASA log entries every 30 seconds with 'deny TCP (no connection) from *** to ***/443 flags FIN ACK on interface management'.  Operation of ASDM is not impacted, but I'd like to correct this if possible.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223973#M859726</guid>
      <dc:creator>mlpalmer</dc:creator>
      <dc:date>2019-03-11T15:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA log - Deny tcp fin ack on int mgmt</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223974#M859727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have exactly the same problem, and would love to know a fix too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 May 2009 14:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223974#M859727</guid>
      <dc:creator>handsy</dc:creator>
      <dc:date>2009-05-19T14:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA log - Deny tcp fin ack on int mgmt</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223975#M859728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Opened a TAC case.  I'll make sure the results get posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 May 2009 17:16:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223975#M859728</guid>
      <dc:creator>mlpalmer</dc:creator>
      <dc:date>2009-05-22T17:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA log - Deny tcp fin ack on int mgmt</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223976#M859729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did a recreate in my lab.I saw the exact same behaviour.&lt;/P&gt;&lt;P&gt;What we all are seeing appears to be a normal behavior.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;When you load up ASDM, there is one main connection to the ASA interface on port 443 via which GUI is populated. The other possible connection&lt;/P&gt;&lt;P&gt;could be logging connection via which ASDM gets logs from ASA. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Apart from this, if there is any command which you need to execute from ASDM, or when you navigate through ASDM windows/frames, most of them would cause ASDM to send a command to ASA and use the output to populate&lt;/P&gt;&lt;P&gt;the fields on GUI. These commands are *not* sent on the same connection via which GUI is visible, but via a new separate connection. As soon as&lt;/P&gt;&lt;P&gt;ASA gets the output, the connection is closed and the FIN+ACK is denied because connection no longer exists. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 May 2009 19:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223976#M859729</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2009-05-22T19:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA log - Deny tcp fin ack on int mgmt</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223977#M859730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is exactly my point and I would view this as a deficiency.  The ASA should be able to properly terminate connections, especially from / to itself.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Let me know if you agree or disagree with the assessment.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Also, I opened a dialog on NetPro on this topic.  Would you be willing to post your respose there too?  At least one other person was seeking a resolution for this issue.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Mike Palmer&lt;/P&gt;&lt;P&gt;Bremer Financial.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 May 2009 19:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-deny-tcp-fin-ack-on-int-mgmt/m-p/1223977#M859730</guid>
      <dc:creator>mlpalmer</dc:creator>
      <dc:date>2009-05-22T19:19:25Z</dc:date>
    </item>
  </channel>
</rss>

