<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic client sending tcp resets in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/client-sending-tcp-resets/m-p/833351#M969699</link>
    <description>&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;update&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;i guess the client is just doing what it is suppose to do when you have a routing loop and the client is getting a syn instead of a syn-ack&lt;/P&gt;&lt;P&gt;case closed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a recently created FWSM context.  Currently i have a rule says.&lt;/P&gt;&lt;P&gt;"any host x.x.x.x any".  I am able to send udp or icmp to that host but any attempts to send tcp to that host results in a tcp reset being sent from the client. example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(inside host) tcp ftp syn&lt;/P&gt;&lt;P&gt;(outside host) tcp ftp ack&lt;/P&gt;&lt;P&gt;(inside host) tcp ftp rst&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then the outside host tries to complet the connection build, but its rejected by the firewall because the connection is no longer in the state table.&lt;/P&gt;&lt;P&gt;This happens with any client that I use on this firewall context.  also if I move this client to another firewall context this does not happen.  has anyone seen this behavior before?  what causes the client to send the tcp reset?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM Firewall Version 3.1(4) &amp;lt;context&amp;gt;&lt;/P&gt;&lt;P&gt;Device Manager Version 5.0(2)F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:09:27 GMT</pubDate>
    <dc:creator>BARRY GROSS</dc:creator>
    <dc:date>2019-03-11T11:09:27Z</dc:date>
    <item>
      <title>client sending tcp resets</title>
      <link>https://community.cisco.com/t5/network-security/client-sending-tcp-resets/m-p/833351#M969699</link>
      <description>&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;update&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;i guess the client is just doing what it is suppose to do when you have a routing loop and the client is getting a syn instead of a syn-ack&lt;/P&gt;&lt;P&gt;case closed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a recently created FWSM context.  Currently i have a rule says.&lt;/P&gt;&lt;P&gt;"any host x.x.x.x any".  I am able to send udp or icmp to that host but any attempts to send tcp to that host results in a tcp reset being sent from the client. example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(inside host) tcp ftp syn&lt;/P&gt;&lt;P&gt;(outside host) tcp ftp ack&lt;/P&gt;&lt;P&gt;(inside host) tcp ftp rst&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then the outside host tries to complet the connection build, but its rejected by the firewall because the connection is no longer in the state table.&lt;/P&gt;&lt;P&gt;This happens with any client that I use on this firewall context.  also if I move this client to another firewall context this does not happen.  has anyone seen this behavior before?  what causes the client to send the tcp reset?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM Firewall Version 3.1(4) &amp;lt;context&amp;gt;&lt;/P&gt;&lt;P&gt;Device Manager Version 5.0(2)F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:09:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/client-sending-tcp-resets/m-p/833351#M969699</guid>
      <dc:creator>BARRY GROSS</dc:creator>
      <dc:date>2019-03-11T11:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: client sending tcp resets</title>
      <link>https://community.cisco.com/t5/network-security/client-sending-tcp-resets/m-p/833352#M969700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What type of ftp are u  trying to do ?&lt;/P&gt;&lt;P&gt;the client is located in the inside and the server is located at the outside .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have u got the fixups enabled or diabled ?&lt;/P&gt;&lt;P&gt;if it is disabled this can be a cause for the problem &lt;/P&gt;&lt;P&gt;To check for detailed info have u run the captures on the firewall ?&lt;/P&gt;&lt;P&gt;Also have u checked the syslog messages at the debugging level? It might give u an idea why the cleint is sending the reset message ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2007 06:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/client-sending-tcp-resets/m-p/833352#M969700</guid>
      <dc:creator>rajbhatt</dc:creator>
      <dc:date>2007-09-13T06:09:51Z</dc:date>
    </item>
  </channel>
</rss>

