<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5520 ASA-4-419002: Duplicate TCP SYN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952775#M940968</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a problem, the connection between hosts on my network is not possible. I becam this Error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; %ASA-4-419002: Duplicate TCP SYN OUTSIDE:10.10.66.2/1507 to INSIDE:10.10.1.6/1507 with different initial sequence number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network behind the ASA's OUTSIDE interface is completely under my &lt;/P&gt;&lt;P&gt;control, with the ASA being the only gateway, so I'm reasonably sure &lt;/P&gt;&lt;P&gt;there's no source IP address spoofing going on. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what cann i do, to resolve this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:17:32 GMT</pubDate>
    <dc:creator>marie-pongou</dc:creator>
    <dc:date>2019-03-11T12:17:32Z</dc:date>
    <item>
      <title>ASA 5520 ASA-4-419002: Duplicate TCP SYN</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952775#M940968</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a problem, the connection between hosts on my network is not possible. I becam this Error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; %ASA-4-419002: Duplicate TCP SYN OUTSIDE:10.10.66.2/1507 to INSIDE:10.10.1.6/1507 with different initial sequence number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network behind the ASA's OUTSIDE interface is completely under my &lt;/P&gt;&lt;P&gt;control, with the ASA being the only gateway, so I'm reasonably sure &lt;/P&gt;&lt;P&gt;there's no source IP address spoofing going on. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what cann i do, to resolve this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952775#M940968</guid>
      <dc:creator>marie-pongou</dc:creator>
      <dc:date>2019-03-11T12:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ASA-4-419002: Duplicate TCP SYN</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952776#M940970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible to stop the Spoofing-Feature on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marie&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Mar 2008 07:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952776#M940970</guid>
      <dc:creator>marie-pongou</dc:creator>
      <dc:date>2008-03-19T07:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ASA-4-419002: Duplicate TCP SYN</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952777#M940973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="medium_text" id="result_box"&gt;&lt;SPAN style="font-size: 12pt; background-color: #fff; "&gt;I had a problem exactly the same. &lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; background-color: #fff; "&gt;After hours of attempts, solved the problem by adding an ACL on the outside interface. &lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;SPAN onmouseout="" onmouseover="" style="background-color: #fff;" title="POr incrivel que pareça, funcionou para mim."&gt;Strangely enough, it worked for me. &lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN onmouseout="" onmouseover="" title="Boa sorte"&gt;Good luck&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Jul 2010 18:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952777#M940973</guid>
      <dc:creator>iprojetos</dc:creator>
      <dc:date>2010-07-21T18:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ASA-4-419002: Duplicate TCP SYN</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952778#M940974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;If what you say is true, that this connection is not possible, I.E. your topology should not allow for this, then you need to look into some sort of routing error, perhaps you have a loop somewhere?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA is just reacting to what traffic is receiving, so it must have received this syn on another interface and somehow the packet was also sent outside and received there as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason that denying with an access-list will work is that the packet will hit the access-list and drop before it can be checked to see if it is a duplicate syn.&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Jul 2010 18:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-asa-4-419002-duplicate-tcp-syn/m-p/952778#M940974</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-07-21T18:50:40Z</dc:date>
    </item>
  </channel>
</rss>

