<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Teardown TCP connection 0 SYN timeout in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-0-syn-timeout/m-p/3414920#M950949</link>
    <description>&lt;P&gt;Hello everyone:&lt;/P&gt;
&lt;P&gt;I am pretty new and I am becoming crazy with something is suposed to be easy, so thanks in advance.&lt;/P&gt;
&lt;P&gt;I´ll try to explain the scenario:&lt;/P&gt;
&lt;P&gt;We have a business lan with ip range (10.154.X.X/22 ) and wireless lan(192.168.2.0/24)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This environment is connected to a Cisco ASA firewall 1&lt;/P&gt;
&lt;P&gt;This cisco ASA is connected with ip 172.16.1.100 in the outside interface to a dummy switch&lt;/P&gt;
&lt;P&gt;this switch is connected to a secondary firewall 2 with outside ip 172.16.1.1&lt;/P&gt;
&lt;P&gt;in the inside interface the IP is 190.167.0.1&lt;/P&gt;
&lt;P&gt;in this last LAN we have a Webserver with IP 190.16.0.34&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-----Business LAN----- FIREWALL1--(172.16.1.100)----------SWITCH-----------(172.16.1.1)--FIREWALL2--(190.167.0.1)--------WEBSERVER(190.167.0.34)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately the Webserver was designed in an isolated environement and the IP is public, that is why there is a NAT in Firewall 1 to translate 10.154.X.97 to 190.167.0.34&lt;/P&gt;
&lt;P&gt;The Wireless network (192.168.2.0) works fine and is able to see the webserver using the NAT address (10.154.X.97) but unfortunately Wired network is not able to reach the webserver or even ping it. I receive the following&amp;nbsp; traces:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;6&amp;nbsp;&amp;nbsp; &amp;nbsp;Jul 12 2018&amp;nbsp;&amp;nbsp; &amp;nbsp;20:10:57&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&amp;nbsp;10.154.X.X &amp;nbsp;&amp;nbsp; 51394&amp;nbsp;&amp;nbsp; &amp;nbsp;190.167.0.34&amp;nbsp;&amp;nbsp; &amp;nbsp;443&amp;nbsp;&amp;nbsp; &amp;nbsp;Built inbound TCP connection 219863 for outside:10.154.X.X/51394 (10.154.X.X/51394) to PlantLan:190.167.0.34/443 (190.167.0.34/443)&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;6&amp;nbsp;&amp;nbsp; &amp;nbsp;Jul 12 2018&amp;nbsp;&amp;nbsp; &amp;nbsp;20:11:06&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&amp;nbsp;10.154.X.X&amp;nbsp;&amp;nbsp;&amp;nbsp; 51392&amp;nbsp;&amp;nbsp; &amp;nbsp;190.167.0.34&amp;nbsp;&amp;nbsp; &amp;nbsp;443&amp;nbsp;&amp;nbsp; &amp;nbsp;Teardown TCP connection 219862 for outside:10.154.X.X/51392 to PlantLan:190.167.0.34/443 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using ASDM so if you want me to write any command in CLI just tell me what to write.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;THANKS SO MUCH IN ADVACE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:58:45 GMT</pubDate>
    <dc:creator>Alfonsoj</dc:creator>
    <dc:date>2020-02-21T15:58:45Z</dc:date>
    <item>
      <title>Teardown TCP connection 0 SYN timeout</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-0-syn-timeout/m-p/3414920#M950949</link>
      <description>&lt;P&gt;Hello everyone:&lt;/P&gt;
&lt;P&gt;I am pretty new and I am becoming crazy with something is suposed to be easy, so thanks in advance.&lt;/P&gt;
&lt;P&gt;I´ll try to explain the scenario:&lt;/P&gt;
&lt;P&gt;We have a business lan with ip range (10.154.X.X/22 ) and wireless lan(192.168.2.0/24)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This environment is connected to a Cisco ASA firewall 1&lt;/P&gt;
&lt;P&gt;This cisco ASA is connected with ip 172.16.1.100 in the outside interface to a dummy switch&lt;/P&gt;
&lt;P&gt;this switch is connected to a secondary firewall 2 with outside ip 172.16.1.1&lt;/P&gt;
&lt;P&gt;in the inside interface the IP is 190.167.0.1&lt;/P&gt;
&lt;P&gt;in this last LAN we have a Webserver with IP 190.16.0.34&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-----Business LAN----- FIREWALL1--(172.16.1.100)----------SWITCH-----------(172.16.1.1)--FIREWALL2--(190.167.0.1)--------WEBSERVER(190.167.0.34)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately the Webserver was designed in an isolated environement and the IP is public, that is why there is a NAT in Firewall 1 to translate 10.154.X.97 to 190.167.0.34&lt;/P&gt;
&lt;P&gt;The Wireless network (192.168.2.0) works fine and is able to see the webserver using the NAT address (10.154.X.97) but unfortunately Wired network is not able to reach the webserver or even ping it. I receive the following&amp;nbsp; traces:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;6&amp;nbsp;&amp;nbsp; &amp;nbsp;Jul 12 2018&amp;nbsp;&amp;nbsp; &amp;nbsp;20:10:57&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&amp;nbsp;10.154.X.X &amp;nbsp;&amp;nbsp; 51394&amp;nbsp;&amp;nbsp; &amp;nbsp;190.167.0.34&amp;nbsp;&amp;nbsp; &amp;nbsp;443&amp;nbsp;&amp;nbsp; &amp;nbsp;Built inbound TCP connection 219863 for outside:10.154.X.X/51394 (10.154.X.X/51394) to PlantLan:190.167.0.34/443 (190.167.0.34/443)&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;6&amp;nbsp;&amp;nbsp; &amp;nbsp;Jul 12 2018&amp;nbsp;&amp;nbsp; &amp;nbsp;20:11:06&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&amp;nbsp;10.154.X.X&amp;nbsp;&amp;nbsp;&amp;nbsp; 51392&amp;nbsp;&amp;nbsp; &amp;nbsp;190.167.0.34&amp;nbsp;&amp;nbsp; &amp;nbsp;443&amp;nbsp;&amp;nbsp; &amp;nbsp;Teardown TCP connection 219862 for outside:10.154.X.X/51392 to PlantLan:190.167.0.34/443 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using ASDM so if you want me to write any command in CLI just tell me what to write.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;THANKS SO MUCH IN ADVACE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-0-syn-timeout/m-p/3414920#M950949</guid>
      <dc:creator>Alfonsoj</dc:creator>
      <dc:date>2020-02-21T15:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Teardown TCP connection 0 SYN timeout</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-0-syn-timeout/m-p/3414962#M950952</link>
      <description>&lt;P&gt;I would recommend using packet-tracers and captures to figure out where the problem is. Run the following packet-tracer commands on both Firewalls:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;packet-tracer input&amp;nbsp;&lt;SPAN&gt;PlantLan tcp 10.154.x.x 51394&amp;nbsp;190.167.0.34 443 detailed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also apply captures similar to this on inside and outside interface when you are testing with actual traffic:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;capture capi interface PlantLan match ip host 10.154.x.x&amp;nbsp;host 190.167.0.34&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;capture capo interface outside match ip host&amp;nbsp;10.154.x.x host 190.167.0.34 ( change the source for Firewall2 to NAT ip address)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 20:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-0-syn-timeout/m-p/3414962#M950952</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-07-12T20:26:25Z</dc:date>
    </item>
  </channel>
</rss>

