<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic need help with SYN Timoeout message in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940370#M919374</link>
    <description>&lt;P&gt;hi all, &lt;/P&gt;&lt;P&gt;Im trying to establish a connection from a server sitting behind a dmz interface to a linux box on port 4573 (sitting behind the inside interface) the connection is establish and the access list is allowing the packet through but i then get this message:&lt;/P&gt;&lt;P&gt;"Teardown TCP connection 606 for dmz xx.xx.xx.xx/37595 to inside xx.xx.xx.xx/4573 duration 0:00:30 bytes 0 SYN Timeout"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas why this might be happening?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:51:24 GMT</pubDate>
    <dc:creator>SOL10</dc:creator>
    <dc:date>2019-03-11T12:51:24Z</dc:date>
    <item>
      <title>need help with SYN Timoeout message</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940370#M919374</link>
      <description>&lt;P&gt;hi all, &lt;/P&gt;&lt;P&gt;Im trying to establish a connection from a server sitting behind a dmz interface to a linux box on port 4573 (sitting behind the inside interface) the connection is establish and the access list is allowing the packet through but i then get this message:&lt;/P&gt;&lt;P&gt;"Teardown TCP connection 606 for dmz xx.xx.xx.xx/37595 to inside xx.xx.xx.xx/4573 duration 0:00:30 bytes 0 SYN Timeout"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas why this might be happening?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:51:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940370#M919374</guid>
      <dc:creator>SOL10</dc:creator>
      <dc:date>2019-03-11T12:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: need help with SYN Timoeout message</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940371#M919375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This means that the client was unable to establish a three-way handshake (SYN, SYN-ACK and so on) to the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would check the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Try opening/testing the application from the LAN behind the ASA first, if this is working proceed to the next step.&lt;/P&gt;&lt;P&gt;2) On the internal client that was used for testing in Step (1) check if the service is establishing a connection on the same TCP flow as the one initiated by the client, and there is no dynamic behaviour like in some protocols like FTP, X-Windows etc. This can be done by observing the netstat output using the built-in netstat utility or some third-party package like TcpView.&lt;/P&gt;&lt;P&gt;3) Try troubleshooting with the packet-tracer command on your ASA box&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2008 06:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940371#M919375</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-05-29T06:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: need help with SYN Timoeout message</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940372#M919376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Salaams Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response. The problem was that the traffic was going through the default gateway of the server concerned(which was the inside intf or another asa) when it should it have been going throuhg the inside intf of the asa to which the remote server is connected (off the dmz). I hope this makes sense as we have a very peculiar setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sol&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2008 07:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940372#M919376</guid>
      <dc:creator>SOL10</dc:creator>
      <dc:date>2008-05-29T07:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: need help with SYN Timoeout message</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940373#M919377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wasalam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great to see you have it working now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2008 07:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-syn-timoeout-message/m-p/940373#M919377</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-05-29T07:23:17Z</dc:date>
    </item>
  </channel>
</rss>

