<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP connection Errors and Pix TCP flags.. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926274#M941189</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well Pix/ASA terminates half open connections after certain time, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an embryonic connection where the server did not reply back with SYNACK, either the server was down/or return route was missin, that you need to fix on your server side &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Mar 2008 16:15:53 GMT</pubDate>
    <dc:creator>abinjola</dc:creator>
    <dc:date>2008-03-11T16:15:53Z</dc:date>
    <item>
      <title>TCP connection Errors and Pix TCP flags..</title>
      <link>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926271#M941181</link>
      <description>&lt;P&gt;A remote client tried legitmately to 3 way handshake a TCP connection through our firwall and instead of going into UP state, the TCP connection failed, with the Pix "Show conn" flags showing "SaA" on the client side and "SaAB" flags on the server side. We think we can decode these flags - but we cant figure out the causation. No devices went down or failed-over to my knowledge, and there appears to have been no other reported events occuring that could have caused or impacted this situation. Any ideas anyone as to what may have caused the TCP connection attempt to have failed? It seemed to right itself also after a while - we did nothing...but I need some answers for the suits when it happens again - thanks &lt;A href="mailto:peter@it-123.co.uk" target="_blank"&gt;peter@it-123.co.uk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926271#M941181</guid>
      <dc:creator>peter-net</dc:creator>
      <dc:date>2019-03-11T12:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: TCP connection Errors and Pix TCP flags..</title>
      <link>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926272#M941184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SaAB--&amp;gt;initiat sym from outside, and firewall waiting for synack, there was no returns reply sent to firewall,the default gateway got missing,  check for routing issues...is the client/server having dual NICs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 15:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926272#M941184</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-03-11T15:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: TCP connection Errors and Pix TCP flags..</title>
      <link>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926273#M941186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;not aware of any routing probs, but could the tcp connection have just timed out server side (due to a slow server respnse issue) and this left the connection incomplete?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 16:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926273#M941186</guid>
      <dc:creator>peter-net</dc:creator>
      <dc:date>2008-03-11T16:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: TCP connection Errors and Pix TCP flags..</title>
      <link>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926274#M941189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well Pix/ASA terminates half open connections after certain time, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an embryonic connection where the server did not reply back with SYNACK, either the server was down/or return route was missin, that you need to fix on your server side &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 16:15:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926274#M941189</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-03-11T16:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: TCP connection Errors and Pix TCP flags..</title>
      <link>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926275#M941193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IS it possible to modify the firewall to allow for the time delay and thus allow the connection to succeed if it is a latencty problem from the app?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 16:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-connection-errors-and-pix-tcp-flags/m-p/926275#M941193</guid>
      <dc:creator>peter-net</dc:creator>
      <dc:date>2008-03-11T16:51:48Z</dc:date>
    </item>
  </channel>
</rss>

