<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP denied in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242180#M876192</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on another network.&lt;/P&gt;&lt;P&gt;the devices are on different switchs and different vlans, but all traficc is routed to internal-interface of FW. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Feb 2009 14:31:08 GMT</pubDate>
    <dc:creator>SpeedLottery</dc:creator>
    <dc:date>2009-02-18T14:31:08Z</dc:date>
    <item>
      <title>TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242178#M876189</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to computers (on different VLANS) but pointing to the FW to connect via specific tcp ports. &lt;/P&gt;&lt;P&gt;I'm getting this syslog message.&lt;/P&gt;&lt;P&gt;106015 Deny TCP (no connection) from 192.168.167.64/1433 to 192.168.167.80/1796 flag SYN ACK on internal interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should i add an acl into internal-interface and how?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242178#M876189</guid>
      <dc:creator>SpeedLottery</dc:creator>
      <dc:date>2019-03-11T14:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242179#M876190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Errrm from your post - the traffic is from a device to another device on the same network?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 12:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242179#M876190</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-18T12:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242180#M876192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on another network.&lt;/P&gt;&lt;P&gt;the devices are on different switchs and different vlans, but all traficc is routed to internal-interface of FW. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 14:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242180#M876192</guid>
      <dc:creator>SpeedLottery</dc:creator>
      <dc:date>2009-02-18T14:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242181#M876194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - just one question what is device "192.168.165.61"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;taken from your firewall config:-&lt;/P&gt;&lt;P&gt;"route internal-interface 192.168.167.0 255.255.255.0 192.168.165.61"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 14:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242181#M876194</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-18T14:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242182#M876197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok,&lt;/P&gt;&lt;P&gt;becouse 192.168.165.0 is the internal network, and there is another network on other switch, which i connected with a crossover cable, and so i configured on that third switch an interface from vlan 1 with this 192.1658.165.61 ip, so that the internal network knows how to reach the 192.168.167.0 network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 14:56:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242182#M876197</guid>
      <dc:creator>SpeedLottery</dc:creator>
      <dc:date>2009-02-18T14:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242183#M876199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - here's the thing, what you have done makes no sense, you have multiple layer 3 interfaces on multiple switches, the routing will not be correct or best practise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What device is handling the vlan to vlan IP routing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 15:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242183#M876199</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-18T15:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242184#M876202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I attach the switches config.&lt;/P&gt;&lt;P&gt;ip routing is enabled in all switches, and ping is ok from hosts on vlan30 to hosts on vlan1 but there are issues like the tcp ports that i dont understand.&lt;/P&gt;&lt;P&gt;that's why i said that if the FW is denying the tcp connection i guess i should allow it somehow.&lt;/P&gt;&lt;P&gt;i just need a host on the 192.168.165.0 to connect via specific tcp ports to another host on the 192.168.167.0 network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 15:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242184#M876202</guid>
      <dc:creator>SpeedLottery</dc:creator>
      <dc:date>2009-02-18T15:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242185#M876205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From your configs -  All swithches are effectivly routers, ans switches.  I can see no order, i.e core, distribution, access switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I find it quite surprising that the firewall is seeing a tcp request from 2 machines on vlan30 - as they are in the same broadcast domain and do not need to go thru a layer 3 device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The fact you have 3 layer 3 interfaces and the firewall interface are routable, means there should be no connectivity issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I personally think you should re-think your design.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 15:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242185#M876205</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-18T15:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242186#M876208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The machines are on different vlans, 1 and 30.&lt;/P&gt;&lt;P&gt;one has 192.168.167.80&lt;/P&gt;&lt;P&gt;the other 192.168.165.64&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 15:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242186#M876208</guid>
      <dc:creator>SpeedLottery</dc:creator>
      <dc:date>2009-02-18T15:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: TCP denied</title>
      <link>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242187#M876214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh yes - OK here is the quick and dirty fix:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ASA remove the route:-&lt;/P&gt;&lt;P&gt;route internal-interface 192.168.167.0 255.255.255.0 192.168.165.61&lt;/P&gt;&lt;P&gt;replace with:-&lt;/P&gt;&lt;P&gt;route internal-interface 192.168.167.0 255.255.255.0 192.168.165.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In NS1 add:-&lt;/P&gt;&lt;P&gt;ip route 192.168.167.0 255.255.255.0 192.168.165.61&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In NS2 add:-&lt;/P&gt;&lt;P&gt;ip route 192.168.167.0 255.255.255.0 192.168.165.61&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I strongly suggest you change your topology as right now - you have 3 routers, with no logical routing process between them and poor design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 19:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-denied/m-p/1242187#M876214</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-18T19:14:06Z</dc:date>
    </item>
  </channel>
</rss>

