<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Return traffic from port 80 denied in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061327#M914757</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;I've seen this type of error when there are routing problems in ACTIVE-ACTIVE firewall configurations, but this doesn't seem to be your case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Aug 2008 13:43:33 GMT</pubDate>
    <dc:creator>joe.favia</dc:creator>
    <dc:date>2008-08-13T13:43:33Z</dc:date>
    <item>
      <title>Return traffic from port 80 denied</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061322#M914752</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have seen this a lot with routers and PIXs. Traffic with a source port of port 80 and destination of a dynamic port is denied on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic is from legitimate web servers that users are browsing through the NATed inspected interface. The websites appear to be working fine though. It does produce a lot of denies in my MARS logging though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It this normal or do I have a config problem? Is there something up with the web server not returning traffic correctly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the sanitised config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:29:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061322#M914752</guid>
      <dc:creator>scottyd</dc:creator>
      <dc:date>2019-03-11T13:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from port 80 denied</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061323#M914753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try to add the &lt;/P&gt;&lt;P&gt;inspect http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to the &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2008 05:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061323#M914753</guid>
      <dc:creator>Marwan ALshawi</dc:creator>
      <dc:date>2008-08-12T05:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from port 80 denied</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061324#M914754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seeing something similar on ASAs with 7.2(4): very, very busy logging because of connections that are "denied" usually related to the regular traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best explanation I have so far (I'm still researching) is that the client connections (or server, for that matter) are being closed with TCP Resets from one side and any traffic from the other side gets immediately denied as the PIX/ASA clears the state table for that connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is also making a mess of my MARS logging...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2008 11:25:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061324#M914754</guid>
      <dc:creator>fsmontenegro</dc:creator>
      <dc:date>2008-08-12T11:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from port 80 denied</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061325#M914755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would start by taking a look at a couple of things:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Do you see the connection being built as the initial SYN comes through? If so, what interfaces is the connection built between?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. What do the syslogs show as a deny reason? If you see the packet being denied due to "no connection", do the interfaces involved match the ones that you saw when the connection was built?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Often times, this behavior will be caused by asymmetric routing/alternate paths to the Internet in your network. As an example, the initial SYN of the TCP connection may find its way out to the Internet through a path other than the firewall. The web server will still receive this SYN and respond with a SYN-ACK as expected. However, when this SYN-ACK hits the outside interface of the ASA, the ASA will drop the traffic because it never saw the initial SYN and it believes that the SYN-ACK is unsolicited.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at the syslogs that show if the initial connection is being built and also the logs that show the reason why the return traffic is being denied. Also, packet captures will be useful in figuring out exactly how the packets are flowing through your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2008 21:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061325#M914755</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-12T21:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from port 80 denied</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061326#M914756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks all for your feedback.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried the inspect http command and have yet to see traffic on port 80 being denied. Not sure if it has been resolved yet. However I am still getting problems for HTTPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me that the connection is built up then it is torn down 10 seconds later and packets are denied. Then it is built up again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the log from MARS. It is in reverse order in time. I have replaced the public IP with 1.1.1.1 and the website as 2.2.2.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2008 21:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061326#M914756</guid>
      <dc:creator>scottyd</dc:creator>
      <dc:date>2008-08-12T21:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from port 80 denied</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061327#M914757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;I've seen this type of error when there are routing problems in ACTIVE-ACTIVE firewall configurations, but this doesn't seem to be your case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2008 13:43:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061327#M914757</guid>
      <dc:creator>joe.favia</dc:creator>
      <dc:date>2008-08-13T13:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from port 80 denied</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061328#M914758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the logs show your connection being torn down due to normal TCP FINs. I would recommend getting packet captures on both sides of the firewall to see exactly what the connection looks like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2008 18:21:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061328#M914758</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-13T18:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from port 80 denied</title>
      <link>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061329#M914759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your input so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still can not find the problem. Unfortunatly it is diffcult for me to sniff the traffic, as it is remote to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am also seeing Resets tearing down the connection. Is there a way of extending the teardown time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;134&amp;gt;Oct 14 2008 15:48:01: %ASA-6-302014: Teardown TCP connection 317Â­7146 for outside:198.133.219.25/80 to inside:172.16.0.29/2158 duration 0:00Â­:02 bytes 5191 TCP Reset-I &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;134&amp;gt;Oct 14 2008 15:48:01: %ASA-6-106100: access-list outside_access_Â­in denied tcp outside/198.133.219.25(80) -&amp;gt; inside/2.2.2.2(44219)Â­ hit-cnt 1 first hit [0x2c1c6a65, 0x0] &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 02:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/return-traffic-from-port-80-denied/m-p/1061329#M914759</guid>
      <dc:creator>scottyd</dc:creator>
      <dc:date>2008-10-14T02:48:45Z</dc:date>
    </item>
  </channel>
</rss>

