<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX Connection Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718817#M970778</link>
    <description>&lt;P&gt;I may be missing something obvious, but would appreciate some help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm attempting to establish new connectivity to an inside server from an outside vendor.  The traffic is being denied with no connection as soon as the conversation is initiated.  I can see the entry in the conn table while the connection is being refused.  Messages in log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;302013: Built inbound TCP connection 479966211 for dmz_vendor:a.b.c.d/52249 (a.b.c.d/52249) to inside:1.2.3.4/80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106015: Deny TCP (no connection) from 1.2.3.4/80 to a.b.c.d/52249 flags SYN ACK  on interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The deny is the very next message in the log, so there is no delay.  At the same time, I was showing the conn table (repeatedly) and saw:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ibk-pix-firewall# sh conn local 1.2.3.4&lt;/P&gt;&lt;P&gt;1808 in use, 5550 most used&lt;/P&gt;&lt;P&gt;TCP out a.b.c.d:52249 in 1.2.3.4:80 idle 0:00:03 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ibk-pix-firewall# sh conn local 1.2.3.4&lt;/P&gt;&lt;P&gt;1820 in use, 5550 most used&lt;/P&gt;&lt;P&gt;TCP out a.b.c.d:52249 in 1.2.3.4:80 idle 0:00:06 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ibk-pix-firewall# sh conn local 1.2.3.4&lt;/P&gt;&lt;P&gt;1794 in use, 5550 most used&lt;/P&gt;&lt;P&gt;TCP out a.b.c.d:52249 in 1.2.3.4:80 idle 0:00:13 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ibk-pix-firewall# sh conn local 1.2.3.4&lt;/P&gt;&lt;P&gt;1788 in use, 5550 most used&lt;/P&gt;&lt;P&gt;TCP out a.b.c.d:52249 in 1.2.3.4:80 idle 0:00:14 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I don't understand why the outgoing packet is being denied for no connection, when the entry is in the conn table.  Any ideas? &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:01:14 GMT</pubDate>
    <dc:creator>msanford3755</dc:creator>
    <dc:date>2019-03-11T11:01:14Z</dc:date>
    <item>
      <title>PIX Connection Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718817#M970778</link>
      <description>&lt;P&gt;I may be missing something obvious, but would appreciate some help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm attempting to establish new connectivity to an inside server from an outside vendor.  The traffic is being denied with no connection as soon as the conversation is initiated.  I can see the entry in the conn table while the connection is being refused.  Messages in log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;302013: Built inbound TCP connection 479966211 for dmz_vendor:a.b.c.d/52249 (a.b.c.d/52249) to inside:1.2.3.4/80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106015: Deny TCP (no connection) from 1.2.3.4/80 to a.b.c.d/52249 flags SYN ACK  on interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The deny is the very next message in the log, so there is no delay.  At the same time, I was showing the conn table (repeatedly) and saw:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ibk-pix-firewall# sh conn local 1.2.3.4&lt;/P&gt;&lt;P&gt;1808 in use, 5550 most used&lt;/P&gt;&lt;P&gt;TCP out a.b.c.d:52249 in 1.2.3.4:80 idle 0:00:03 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ibk-pix-firewall# sh conn local 1.2.3.4&lt;/P&gt;&lt;P&gt;1820 in use, 5550 most used&lt;/P&gt;&lt;P&gt;TCP out a.b.c.d:52249 in 1.2.3.4:80 idle 0:00:06 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ibk-pix-firewall# sh conn local 1.2.3.4&lt;/P&gt;&lt;P&gt;1794 in use, 5550 most used&lt;/P&gt;&lt;P&gt;TCP out a.b.c.d:52249 in 1.2.3.4:80 idle 0:00:13 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ibk-pix-firewall# sh conn local 1.2.3.4&lt;/P&gt;&lt;P&gt;1788 in use, 5550 most used&lt;/P&gt;&lt;P&gt;TCP out a.b.c.d:52249 in 1.2.3.4:80 idle 0:00:14 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I don't understand why the outgoing packet is being denied for no connection, when the entry is in the conn table.  Any ideas? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718817#M970778</guid>
      <dc:creator>msanford3755</dc:creator>
      <dc:date>2019-03-11T11:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Connection Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718818#M970779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike, could you post the access list  for others to see,  strip out public ip info, are you natting from the dmz to the inside if so is the vendor connecting to the nat address instead of your local host IP? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2007 15:05:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718818#M970779</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-08-22T15:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Connection Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718819#M970780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have ACL's restricting traffic inbound at the inside interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2007 15:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718819#M970780</guid>
      <dc:creator>rigoberto.cintron</dc:creator>
      <dc:date>2007-08-22T15:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Connection Problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718820#M970781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi ensure that the following are present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. static NAT for the private IP to a public IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. access list on the outside allowing http access to the Public IP of the server ( as above )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Access group has been applied on the outside interface : )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4 route available to the inside &amp;amp; outside interfaces.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 12:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-connection-problem/m-p/718820#M970781</guid>
      <dc:creator>anandramapathy</dc:creator>
      <dc:date>2007-08-23T12:25:42Z</dc:date>
    </item>
  </channel>
</rss>

