cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6438
Views
0
Helpful
14
Replies

ASA 5510 - Exchange 2007 Outlook anywhere/OWA issue

xfix
Level 1
Level 1

Hi,

We have a ASA 5510 which was running 8.0.2, we recently upgraded it to 8.2.5 and since the upgrade remote users for exchange 2007 are not able to download any large email attachments(over or close to 1MB). This is only happening to Outlook anywhere users or OWA users who are connecting to the exchange server using https(443) externally. If the same users connects internally they do not face any issue. When i check the logs on ASA i am gettings lots of RESET-O and RESET-I entries. Looks like the connection between the client and the server gets reset.

Exchange server sits on the inside network with PAT in place.

Any ideas....

14 Replies 14

manish arora
Level 6
Level 6

Can you please Post the Logs ? as well as output of  sh service-policy ?

Manish

Hi Manish,

Thanks for your reply, see below output from sh service-policy

Global policy:
Service-policy: global_policy
Class-map: inspection_default
Inspect: dns migrated_dns_map_1, packet 870265, drop 11433, reset-drop 0
Inspect: ftp, packet 155, drop 0, reset-drop 0
Inspect: h323 h225 _default_h323_map, packet 0, drop 0, reset-drop 0
tcp-proxy: bytes in buffer 0, bytes dropped 0
Inspect: h323 ras _default_h323_map, packet 9, drop 7, reset-drop 0
Inspect: rsh, packet 0, drop 0, reset-drop 0
Inspect: rtsp, packet 0, drop 0, reset-drop 0
tcp-proxy: bytes in buffer 0, bytes dropped 0
Inspect: sqlnet, packet 0, drop 0, reset-drop 0
Inspect: skinny , packet 0, drop 0, reset-drop 0
tcp-proxy: bytes in buffer 0, bytes dropped 0
Inspect: sunrpc, packet 210, drop 0, reset-drop 0
tcp-proxy: bytes in buffer 0, bytes dropped 0
Inspect: xdmcp, packet 0, drop 0, reset-drop 0
Inspect: netbios, packet 143952, drop 0, reset-drop 0
Inspect: tftp, packet 1, drop 0, reset-drop 0
Inspect: pptp, packet 77430, drop 0, reset-drop 0
Inspect: sip , packet 5, drop 0, reset-drop 0
tcp-proxy: bytes in buffer 0, bytes dropped 0
Inspect: icmp, packet 9897429, drop 39636, reset-drop 0
Inspect: http BlockUrlPolicy, packet 10916492, drop 4211, reset-drop 2291
Inspect: ip-options _default_ip_options_map, packet 0, drop 0, reset-drop 0

Interface LAN:
Service-policy: IM
Class-map: imblock
Inspect: im impolicy, packet 75996195, drop 4, reset-drop 0
tcp-proxy: bytes in buffer 0, bytes dropped 0

Log from ASA while an external client (203.206.x.x) try to receive a 4MB email through outlook 2010 outlookanywhere.

6|Aug 17 2011|10:47:03|302013|203.206.x.x|2610|EmailServerInside|443|Built inbound TCP connection 9502174 for INTERNET:203.206.x.x/2610 (203.206.x.x/2610) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:03|302013|203.206.x.x|2607|EmailServerInside|443|Built inbound TCP connection 9502157 for INTERNET:203.206.x.x/2607 (203.206.x.x/2607) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:04|302013|203.206.x.x|2615|EmailServerInside|443|Built inbound TCP connection 9502202 for INTERNET:203.206.x.x/2615 (203.206.x.x/2615) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:04|302013|203.206.x.x|2616|EmailServerInside|443|Built inbound TCP connection 9502207 for INTERNET:203.206.x.x/2616 (203.206.x.x/2616) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:04|302013|203.206.x.x|2614|EmailServerInside|443|Built inbound TCP connection 9502194 for INTERNET:203.206.x.x/2614 (203.206.x.x/2614) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:04|302013|203.206.x.x|2613|EmailServerInside|443|Built inbound TCP connection 9502191 for INTERNET:203.206.x.x/2613 (203.206.x.x/2613) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:05|302013|203.206.x.x|2624|EmailServerInside|443|Built inbound TCP connection 9502259 for INTERNET:203.206.x.x/2624 (203.206.x.x/2624) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:05|302014|203.206.x.x|2616|EmailServerInside|443|Teardown TCP connection 9502207 for INTERNET:203.206.x.x/2616 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4964 TCP Reset-O

6|Aug 17 2011|10:47:05|302014|203.206.x.x|2614|EmailServerInside|443|Teardown TCP connection 9502194 for INTERNET:203.206.x.x/2614 to LAN:EmailServerInside/443 duration 0:00:01 bytes 5146 TCP Reset-O

6|Aug 17 2011|10:47:06|302013|203.206.x.x|2627|EmailServerInside|443|Built inbound TCP connection 9502276 for INTERNET:203.206.x.x/2627 (203.206.x.x/2627) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:21|302014|203.206.x.x|2624|EmailServerInside|443|Teardown TCP connection 9502259 for INTERNET:203.206.x.x/2624 to LAN:EmailServerInside/443 duration 0:00:15 bytes 4070 TCP Reset-O

6|Aug 17 2011|10:47:21|302014|203.206.x.x|2627|EmailServerInside|443|Teardown TCP connection 9502276 for INTERNET:203.206.x.x/2627 to LAN:EmailServerInside/443 duration 0:00:15 bytes 4304 TCP FINs

6|Aug 17 2011|10:47:32|302013|203.206.x.x|2637|EmailServerInside|443|Built inbound TCP connection 9502772 for INTERNET:203.206.x.x/2637 (203.206.x.x/2637) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:33|302014|203.206.x.x|2638|EmailServerInside|443|Teardown TCP connection 9502776 for INTERNET:203.206.x.x/2638 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|10:47:33|302014|203.206.x.x|2637|EmailServerInside|443|Teardown TCP connection 9502772 for INTERNET:203.206.x.x/2637 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|10:47:33|302013|203.206.x.x|2638|EmailServerInside|443|Built inbound TCP connection 9502776 for INTERNET:203.206.x.x/2638 (203.206.x.x/2638) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:34|302014|203.206.x.x|2640|EmailServerInside|443|Teardown TCP connection 9502792 for INTERNET:203.206.x.x/2640 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP Reset-O

6|Aug 17 2011|10:47:34|302014|203.206.x.x|2639|EmailServerInside|443|Teardown TCP connection 9502790 for INTERNET:203.206.x.x/2639 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|10:47:34|302013|203.206.x.x|2640|EmailServerInside|443|Built inbound TCP connection 9502792 for INTERNET:203.206.x.x/2640 (203.206.x.x/2640) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:34|302013|203.206.x.x|2639|EmailServerInside|443|Built inbound TCP connection 9502790 for INTERNET:203.206.x.x/2639 (203.206.x.x/2639) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:40|302013|203.206.x.x|2643|EmailServerInside|443|Built inbound TCP connection 9502909 for INTERNET:203.206.x.x/2643 (203.206.x.x/2643) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:40|302013|203.206.x.x|2644|EmailServerInside|443|Built inbound TCP connection 9502917 for INTERNET:203.206.x.x/2644 (203.206.x.x/2644) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:40|302014|203.206.x.x|2641|EmailServerInside|443|Teardown TCP connection 9502898 for INTERNET:203.206.x.x/2641 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|10:47:40|302014|203.206.x.x|2642|EmailServerInside|443|Teardown TCP connection 9502901 for INTERNET:203.206.x.x/2642 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|10:47:40|302013|203.206.x.x|2642|EmailServerInside|443|Built inbound TCP connection 9502901 for INTERNET:203.206.x.x/2642 (203.206.x.x/2642) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:40|302013|203.206.x.x|2641|EmailServerInside|443|Built inbound TCP connection 9502898 for INTERNET:203.206.x.x/2641 (203.206.x.x/2641) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:47:41|302014|203.206.x.x|2644|EmailServerInside|443|Teardown TCP connection 9502917 for INTERNET:203.206.x.x/2644 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|10:47:41|302014|203.206.x.x|2643|EmailServerInside|443|Teardown TCP connection 9502909 for INTERNET:203.206.x.x/2643 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4987 TCP FINs

6|Aug 17 2011|10:48:03|302013|203.206.x.x|2646|EmailServerInside|443|Built inbound TCP connection 9503427 for INTERNET:203.206.x.x/2646 (203.206.x.x/2646) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:03|302013|203.206.x.x|2645|EmailServerInside|443|Built inbound TCP connection 9503423 for INTERNET:203.206.x.x/2645 (203.206.x.x/2645) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:04|302013|203.206.x.x|2650|EmailServerInside|443|Built inbound TCP connection 9503451 for INTERNET:203.206.x.x/2650 (203.206.x.x/2650) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:04|302013|203.206.x.x|2647|EmailServerInside|443|Built inbound TCP connection 9503448 for INTERNET:203.206.x.x/2647 (203.206.x.x/2647) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:04|302014|203.206.x.x|2646|EmailServerInside|443|Teardown TCP connection 9503427 for INTERNET:203.206.x.x/2646 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4539 TCP FINs

6|Aug 17 2011|10:48:04|302014|203.206.x.x|2645|EmailServerInside|443|Teardown TCP connection 9503423 for INTERNET:203.206.x.x/2645 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|10:48:08|302014|203.206.x.x|2650|EmailServerInside|443|Teardown TCP connection 9503451 for INTERNET:203.206.x.x/2650 to LAN:EmailServerInside/443 duration 0:00:03 bytes 4102 TCP FINs

6|Aug 17 2011|10:48:08|302014|203.206.x.x|2647|EmailServerInside|443|Teardown TCP connection 9503448 for INTERNET:203.206.x.x/2647 to LAN:EmailServerInside/443 duration 0:00:03 bytes 4038 TCP Reset-O

6|Aug 17 2011|10:48:20|302013|203.206.x.x|2721|EmailServerInside|443|Built inbound TCP connection 9503880 for INTERNET:203.206.x.x/2721 (203.206.x.x/2721) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:20|302013|203.206.x.x|2720|EmailServerInside|443|Built inbound TCP connection 9503876 for INTERNET:203.206.x.x/2720 (203.206.x.x/2720) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:21|302013|203.206.x.x|2723|EmailServerInside|443|Built inbound TCP connection 9503887 for INTERNET:203.206.x.x/2723 (203.206.x.x/2723) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:21|302014|203.206.x.x|2722|EmailServerInside|443|Teardown TCP connection 9503886 for INTERNET:203.206.x.x/2722 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|10:48:21|302014|203.206.x.x|2723|EmailServerInside|443|Teardown TCP connection 9503887 for INTERNET:203.206.x.x/2723 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|10:48:21|302013|203.206.x.x|2722|EmailServerInside|443|Built inbound TCP connection 9503886 for INTERNET:203.206.x.x/2722 (203.206.x.x/2722) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:21|302014|203.206.x.x|2721|EmailServerInside|443|Teardown TCP connection 9503880 for INTERNET:203.206.x.x/2721 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|10:48:21|302014|203.206.x.x|2720|EmailServerInside|443|Teardown TCP connection 9503876 for INTERNET:203.206.x.x/2720 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP Reset-O

6|Aug 17 2011|10:48:34|302014|203.206.x.x|2724|EmailServerInside|443|Teardown TCP connection 9504199 for INTERNET:203.206.x.x/2724 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|10:48:34|302014|203.206.x.x|2725|EmailServerInside|443|Teardown TCP connection 9504205 for INTERNET:203.206.x.x/2725 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|10:48:34|302013|203.206.x.x|2725|EmailServerInside|443|Built inbound TCP connection 9504205 for INTERNET:203.206.x.x/2725 (203.206.x.x/2725) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:34|302013|203.206.x.x|2724|EmailServerInside|443|Built inbound TCP connection 9504199 for INTERNET:203.206.x.x/2724 (203.206.x.x/2724) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:35|302014|203.206.x.x|2726|EmailServerInside|443|Teardown TCP connection 9504209 for INTERNET:203.206.x.x/2726 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|10:48:35|302014|203.206.x.x|2727|EmailServerInside|443|Teardown TCP connection 9504220 for INTERNET:203.206.x.x/2727 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|10:48:35|302013|203.206.x.x|2727|EmailServerInside|443|Built inbound TCP connection 9504220 for INTERNET:203.206.x.x/2727 (203.206.x.x/2727) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:35|302013|203.206.x.x|2726|EmailServerInside|443|Built inbound TCP connection 9504209 for INTERNET:203.206.x.x/2726 (203.206.x.x/2726) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:39|302014|203.206.x.x|2729|EmailServerInside|443|Teardown TCP connection 9504287 for INTERNET:203.206.x.x/2729 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4304 TCP FINs

6|Aug 17 2011|10:48:39|302014|203.206.x.x|2728|EmailServerInside|443|Teardown TCP connection 9504285 for INTERNET:203.206.x.x/2728 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4070 TCP FINs

6|Aug 17 2011|10:48:39|302013|203.206.x.x|2729|EmailServerInside|443|Built inbound TCP connection 9504287 for INTERNET:203.206.x.x/2729 (203.206.x.x/2729) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|10:48:39|302013|203.206.x.x|2728|EmailServerInside|443|Built inbound TCP connection 9504285 for INTERNET:203.206.x.x/2728 (203.206.x.x/2728) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:20|302013|203.206.x.x|2920|EmailServerInside|443|Built inbound TCP connection 9525066 for INTERNET:203.206.x.x/2920 (203.206.x.x/2920) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:20|302013|203.206.x.x|2919|EmailServerInside|443|Built inbound TCP connection 9525059 for INTERNET:203.206.x.x/2919 (203.206.x.x/2919) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:21|302013|203.206.x.x|2922|EmailServerInside|443|Built inbound TCP connection 9525090 for INTERNET:203.206.x.x/2922 (203.206.x.x/2922) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:21|302013|203.206.x.x|2921|EmailServerInside|443|Built inbound TCP connection 9525082 for INTERNET:203.206.x.x/2921 (203.206.x.x/2921) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:21|302014|203.206.x.x|2919|EmailServerInside|443|Teardown TCP connection 9525059 for INTERNET:203.206.x.x/2919 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP Reset-O

6|Aug 17 2011|11:01:21|302014|203.206.x.x|2920|EmailServerInside|443|Teardown TCP connection 9525066 for INTERNET:203.206.x.x/2920 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|11:01:22|302014|203.206.x.x|2921|EmailServerInside|443|Teardown TCP connection 9525082 for INTERNET:203.206.x.x/2921 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|11:01:22|302014|203.206.x.x|2922|EmailServerInside|443|Teardown TCP connection 9525090 for INTERNET:203.206.x.x/2922 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP Reset-O

6|Aug 17 2011|11:01:28|302013|203.206.x.x|2923|EmailServerInside|443|Built inbound TCP connection 9525318 for INTERNET:203.206.x.x/2923 (203.206.x.x/2923) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:31|302013|203.206.x.x|2924|EmailServerInside|443|Built inbound TCP connection 9525380 for INTERNET:203.206.x.x/2924 (203.206.x.x/2924) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:32|302013|203.206.x.x|2925|EmailServerInside|443|Built inbound TCP connection 9525412 for INTERNET:203.206.x.x/2925 (203.206.x.x/2925) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:32|302014|203.206.x.x|2924|EmailServerInside|443|Teardown TCP connection 9525380 for INTERNET:203.206.x.x/2924 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4102 TCP FINs

6|Aug 17 2011|11:01:32|302014|203.206.x.x|2923|EmailServerInside|443|Teardown TCP connection 9525318 for INTERNET:203.206.x.x/2923 to LAN:EmailServerInside/443 duration 0:00:03 bytes 5418 TCP FINs

6|Aug 17 2011|11:01:33|302013|203.206.x.x|2926|EmailServerInside|443|Built inbound TCP connection 9525458 for INTERNET:203.206.x.x/2926 (203.206.x.x/2926) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:35|302014|203.206.x.x|2926|EmailServerInside|443|Teardown TCP connection 9525458 for INTERNET:203.206.x.x/2926 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4102 TCP FINs

6|Aug 17 2011|11:01:35|302014|203.206.x.x|2925|EmailServerInside|443|Teardown TCP connection 9525412 for INTERNET:203.206.x.x/2925 to LAN:EmailServerInside/443 duration 0:00:02 bytes 4038 TCP FINs

6|Aug 17 2011|11:01:46|302013|203.206.x.x|2928|EmailServerInside|443|Built inbound TCP connection 9525759 for INTERNET:203.206.x.x/2928 (203.206.x.x/2928) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:47|302013|203.206.x.x|2929|EmailServerInside|443|Built inbound TCP connection 9525778 for INTERNET:203.206.x.x/2929 (203.206.x.x/2929) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:49|302014|203.206.x.x|2929|EmailServerInside|443|Teardown TCP connection 9525778 for INTERNET:203.206.x.x/2929 to LAN:EmailServerInside/443 duration 0:00:02 bytes 4102 TCP FINs

6|Aug 17 2011|11:01:49|302014|203.206.x.x|2928|EmailServerInside|443|Teardown TCP connection 9525759 for INTERNET:203.206.x.x/2928 to LAN:EmailServerInside/443 duration 0:00:03 bytes 4038 TCP FINs

6|Aug 17 2011|11:01:50|302013|203.206.x.x|2936|EmailServerInside|443|Built inbound TCP connection 9525890 for INTERNET:203.206.x.x/2936 (203.206.x.x/2936) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:50|302013|203.206.x.x|2935|EmailServerInside|443|Built inbound TCP connection 9525876 for INTERNET:203.206.x.x/2935 (203.206.x.x/2935) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:01:51|302014|203.206.x.x|2936|EmailServerInside|443|Teardown TCP connection 9525890 for INTERNET:203.206.x.x/2936 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|11:01:51|302014|203.206.x.x|2935|EmailServerInside|443|Teardown TCP connection 9525876 for INTERNET:203.206.x.x/2935 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4038 TCP FINs

6|Aug 17 2011|11:02:02|302013|203.206.x.x|2939|EmailServerInside|443|Built inbound TCP connection 9526250 for INTERNET:203.206.x.x/2939 (203.206.x.x/2939) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:02:03|302014|203.206.x.x|2943|EmailServerInside|443|Teardown TCP connection 9526278 for INTERNET:203.206.x.x/2943 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|11:02:03|302013|203.206.x.x|2942|EmailServerInside|443|Built inbound TCP connection 9526272 for INTERNET:203.206.x.x/2942 (203.206.x.x/2942) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:02:03|302013|203.206.x.x|2943|EmailServerInside|443|Built inbound TCP connection 9526278 for INTERNET:203.206.x.x/2943 (203.206.x.x/2943) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:02:03|302014|203.206.x.x|2942|EmailServerInside|443|Teardown TCP connection 9526272 for INTERNET:203.206.x.x/2942 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs

6|Aug 17 2011|11:02:03|302014|203.206.x.x|2941|EmailServerInside|443|Teardown TCP connection 9526255 for INTERNET:203.206.x.x/2941 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs

6|Aug 17 2011|11:02:03|302014|203.206.x.x|2939|EmailServerInside|443|Teardown TCP connection 9526250 for INTERNET:203.206.x.x/2939 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4158 TCP FINs

6|Aug 17 2011|11:02:03|302013|203.206.x.x|2941|EmailServerInside|443|Built inbound TCP connection 9526255 for INTERNET:203.206.x.x/2941 (203.206.x.x/2941) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:04:13|302013|203.206.x.x|2974|EmailServerInside|443|Built inbound TCP connection 9530126 for INTERNET:203.206.x.x/2974 (203.206.x.x/2974) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:04:13|302013|203.206.x.x|2973|EmailServerInside|443|Built inbound TCP connection 9530123 for INTERNET:203.206.x.x/2973 (203.206.x.x/2973) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:04:16|302014|203.206.x.x|2979|EmailServerInside|443|Teardown TCP connection 9530221 for INTERNET:203.206.x.x/2979 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4070 TCP FINs

6|Aug 17 2011|11:04:16|302014|203.206.x.x|2980|EmailServerInside|443|Teardown TCP connection 9530229 for INTERNET:203.206.x.x/2980 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4304 TCP FINs

6|Aug 17 2011|11:04:16|302013|203.206.x.x|2979|EmailServerInside|443|Built inbound TCP connection 9530221 for INTERNET:203.206.x.x/2979 (203.206.x.x/2979) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:04:16|302013|203.206.x.x|2980|EmailServerInside|443|Built inbound TCP connection 9530229 for INTERNET:203.206.x.x/2980 (203.206.x.x/2980) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:04:16|302014|203.206.x.x|2974|EmailServerInside|443|Teardown TCP connection 9530126 for INTERNET:203.206.x.x/2974 to LAN:EmailServerInside/443 duration 0:00:02 bytes 5188 TCP Reset-O

6|Aug 17 2011|11:04:16|302014|203.206.x.x|2973|EmailServerInside|443|Teardown TCP connection 9530123 for INTERNET:203.206.x.x/2973 to LAN:EmailServerInside/443 duration 0:00:02 bytes 5146 TCP Reset-O

6|Aug 17 2011|11:04:18|302013|203.206.x.x|2982|EmailServerInside|443|Built inbound TCP connection 9530298 for INTERNET:203.206.x.x/2982 (203.206.x.x/2982) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:04:18|302013|203.206.x.x|2981|EmailServerInside|443|Built inbound TCP connection 9530292 for INTERNET:203.206.x.x/2981 (203.206.x.x/2981) to LAN:EmailServerInside/443 (EmailServerOutside/443)

6|Aug 17 2011|11:04:19|302014|203.206.x.x|2981|EmailServerInside|443|Teardown TCP connection 9530292 for INTERNET:203.206.x.x/2981 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4070 TCP FINs

6|Aug 17 2011|11:04:19|302014|203.206.x.x|2982|EmailServerInside|443|Teardown TCP connection 9530298 for INTERNET:203.206.x.x/2982 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4630 TCP FINs6|Aug 17 2011|10:47:03|302013|203.206.x.x|2610|EmailServerInside|443|Built inbound TCP connection 9502174 for INTERNET:203.206.x.x/2610 (203.206.x.x/2610) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:03|302013|203.206.x.x|2607|EmailServerInside|443|Built inbound TCP connection 9502157 for INTERNET:203.206.x.x/2607 (203.206.x.x/2607) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:04|302013|203.206.x.x|2615|EmailServerInside|443|Built inbound TCP connection 9502202 for INTERNET:203.206.x.x/2615 (203.206.x.x/2615) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:04|302013|203.206.x.x|2616|EmailServerInside|443|Built inbound TCP connection 9502207 for INTERNET:203.206.x.x/2616 (203.206.x.x/2616) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:04|302013|203.206.x.x|2614|EmailServerInside|443|Built inbound TCP connection 9502194 for INTERNET:203.206.x.x/2614 (203.206.x.x/2614) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:04|302013|203.206.x.x|2613|EmailServerInside|443|Built inbound TCP connection 9502191 for INTERNET:203.206.x.x/2613 (203.206.x.x/2613) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:05|302013|203.206.x.x|2624|EmailServerInside|443|Built inbound TCP connection 9502259 for INTERNET:203.206.x.x/2624 (203.206.x.x/2624) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:05|302014|203.206.x.x|2616|EmailServerInside|443|Teardown TCP connection 9502207 for INTERNET:203.206.x.x/2616 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4964 TCP Reset-O
6|Aug 17 2011|10:47:05|302014|203.206.x.x|2614|EmailServerInside|443|Teardown TCP connection 9502194 for INTERNET:203.206.x.x/2614 to LAN:EmailServerInside/443 duration 0:00:01 bytes 5146 TCP Reset-O
6|Aug 17 2011|10:47:06|302013|203.206.x.x|2627|EmailServerInside|443|Built inbound TCP connection 9502276 for INTERNET:203.206.x.x/2627 (203.206.x.x/2627) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:21|302014|203.206.x.x|2624|EmailServerInside|443|Teardown TCP connection 9502259 for INTERNET:203.206.x.x/2624 to LAN:EmailServerInside/443 duration 0:00:15 bytes 4070 TCP Reset-O
6|Aug 17 2011|10:47:21|302014|203.206.x.x|2627|EmailServerInside|443|Teardown TCP connection 9502276 for INTERNET:203.206.x.x/2627 to LAN:EmailServerInside/443 duration 0:00:15 bytes 4304 TCP FINs
6|Aug 17 2011|10:47:32|302013|203.206.x.x|2637|EmailServerInside|443|Built inbound TCP connection 9502772 for INTERNET:203.206.x.x/2637 (203.206.x.x/2637) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:33|302014|203.206.x.x|2638|EmailServerInside|443|Teardown TCP connection 9502776 for INTERNET:203.206.x.x/2638 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|10:47:33|302014|203.206.x.x|2637|EmailServerInside|443|Teardown TCP connection 9502772 for INTERNET:203.206.x.x/2637 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|10:47:33|302013|203.206.x.x|2638|EmailServerInside|443|Built inbound TCP connection 9502776 for INTERNET:203.206.x.x/2638 (203.206.x.x/2638) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:34|302014|203.206.x.x|2640|EmailServerInside|443|Teardown TCP connection 9502792 for INTERNET:203.206.x.x/2640 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP Reset-O
6|Aug 17 2011|10:47:34|302014|203.206.x.x|2639|EmailServerInside|443|Teardown TCP connection 9502790 for INTERNET:203.206.x.x/2639 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|10:47:34|302013|203.206.x.x|2640|EmailServerInside|443|Built inbound TCP connection 9502792 for INTERNET:203.206.x.x/2640 (203.206.x.x/2640) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:34|302013|203.206.x.x|2639|EmailServerInside|443|Built inbound TCP connection 9502790 for INTERNET:203.206.x.x/2639 (203.206.x.x/2639) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:40|302013|203.206.x.x|2643|EmailServerInside|443|Built inbound TCP connection 9502909 for INTERNET:203.206.x.x/2643 (203.206.x.x/2643) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:40|302013|203.206.x.x|2644|EmailServerInside|443|Built inbound TCP connection 9502917 for INTERNET:203.206.x.x/2644 (203.206.x.x/2644) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:40|302014|203.206.x.x|2641|EmailServerInside|443|Teardown TCP connection 9502898 for INTERNET:203.206.x.x/2641 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|10:47:40|302014|203.206.x.x|2642|EmailServerInside|443|Teardown TCP connection 9502901 for INTERNET:203.206.x.x/2642 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|10:47:40|302013|203.206.x.x|2642|EmailServerInside|443|Built inbound TCP connection 9502901 for INTERNET:203.206.x.x/2642 (203.206.x.x/2642) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:40|302013|203.206.x.x|2641|EmailServerInside|443|Built inbound TCP connection 9502898 for INTERNET:203.206.x.x/2641 (203.206.x.x/2641) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:47:41|302014|203.206.x.x|2644|EmailServerInside|443|Teardown TCP connection 9502917 for INTERNET:203.206.x.x/2644 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|10:47:41|302014|203.206.x.x|2643|EmailServerInside|443|Teardown TCP connection 9502909 for INTERNET:203.206.x.x/2643 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4987 TCP FINs
6|Aug 17 2011|10:48:03|302013|203.206.x.x|2646|EmailServerInside|443|Built inbound TCP connection 9503427 for INTERNET:203.206.x.x/2646 (203.206.x.x/2646) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:03|302013|203.206.x.x|2645|EmailServerInside|443|Built inbound TCP connection 9503423 for INTERNET:203.206.x.x/2645 (203.206.x.x/2645) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:04|302013|203.206.x.x|2650|EmailServerInside|443|Built inbound TCP connection 9503451 for INTERNET:203.206.x.x/2650 (203.206.x.x/2650) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:04|302013|203.206.x.x|2647|EmailServerInside|443|Built inbound TCP connection 9503448 for INTERNET:203.206.x.x/2647 (203.206.x.x/2647) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:04|302014|203.206.x.x|2646|EmailServerInside|443|Teardown TCP connection 9503427 for INTERNET:203.206.x.x/2646 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4539 TCP FINs
6|Aug 17 2011|10:48:04|302014|203.206.x.x|2645|EmailServerInside|443|Teardown TCP connection 9503423 for INTERNET:203.206.x.x/2645 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|10:48:08|302014|203.206.x.x|2650|EmailServerInside|443|Teardown TCP connection 9503451 for INTERNET:203.206.x.x/2650 to LAN:EmailServerInside/443 duration 0:00:03 bytes 4102 TCP FINs
6|Aug 17 2011|10:48:08|302014|203.206.x.x|2647|EmailServerInside|443|Teardown TCP connection 9503448 for INTERNET:203.206.x.x/2647 to LAN:EmailServerInside/443 duration 0:00:03 bytes 4038 TCP Reset-O
6|Aug 17 2011|10:48:20|302013|203.206.x.x|2721|EmailServerInside|443|Built inbound TCP connection 9503880 for INTERNET:203.206.x.x/2721 (203.206.x.x/2721) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:20|302013|203.206.x.x|2720|EmailServerInside|443|Built inbound TCP connection 9503876 for INTERNET:203.206.x.x/2720 (203.206.x.x/2720) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:21|302013|203.206.x.x|2723|EmailServerInside|443|Built inbound TCP connection 9503887 for INTERNET:203.206.x.x/2723 (203.206.x.x/2723) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:21|302014|203.206.x.x|2722|EmailServerInside|443|Teardown TCP connection 9503886 for INTERNET:203.206.x.x/2722 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|10:48:21|302014|203.206.x.x|2723|EmailServerInside|443|Teardown TCP connection 9503887 for INTERNET:203.206.x.x/2723 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|10:48:21|302013|203.206.x.x|2722|EmailServerInside|443|Built inbound TCP connection 9503886 for INTERNET:203.206.x.x/2722 (203.206.x.x/2722) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:21|302014|203.206.x.x|2721|EmailServerInside|443|Teardown TCP connection 9503880 for INTERNET:203.206.x.x/2721 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|10:48:21|302014|203.206.x.x|2720|EmailServerInside|443|Teardown TCP connection 9503876 for INTERNET:203.206.x.x/2720 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP Reset-O
6|Aug 17 2011|10:48:34|302014|203.206.x.x|2724|EmailServerInside|443|Teardown TCP connection 9504199 for INTERNET:203.206.x.x/2724 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|10:48:34|302014|203.206.x.x|2725|EmailServerInside|443|Teardown TCP connection 9504205 for INTERNET:203.206.x.x/2725 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|10:48:34|302013|203.206.x.x|2725|EmailServerInside|443|Built inbound TCP connection 9504205 for INTERNET:203.206.x.x/2725 (203.206.x.x/2725) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:34|302013|203.206.x.x|2724|EmailServerInside|443|Built inbound TCP connection 9504199 for INTERNET:203.206.x.x/2724 (203.206.x.x/2724) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:35|302014|203.206.x.x|2726|EmailServerInside|443|Teardown TCP connection 9504209 for INTERNET:203.206.x.x/2726 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|10:48:35|302014|203.206.x.x|2727|EmailServerInside|443|Teardown TCP connection 9504220 for INTERNET:203.206.x.x/2727 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|10:48:35|302013|203.206.x.x|2727|EmailServerInside|443|Built inbound TCP connection 9504220 for INTERNET:203.206.x.x/2727 (203.206.x.x/2727) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:35|302013|203.206.x.x|2726|EmailServerInside|443|Built inbound TCP connection 9504209 for INTERNET:203.206.x.x/2726 (203.206.x.x/2726) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:39|302014|203.206.x.x|2729|EmailServerInside|443|Teardown TCP connection 9504287 for INTERNET:203.206.x.x/2729 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4304 TCP FINs
6|Aug 17 2011|10:48:39|302014|203.206.x.x|2728|EmailServerInside|443|Teardown TCP connection 9504285 for INTERNET:203.206.x.x/2728 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4070 TCP FINs
6|Aug 17 2011|10:48:39|302013|203.206.x.x|2729|EmailServerInside|443|Built inbound TCP connection 9504287 for INTERNET:203.206.x.x/2729 (203.206.x.x/2729) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|10:48:39|302013|203.206.x.x|2728|EmailServerInside|443|Built inbound TCP connection 9504285 for INTERNET:203.206.x.x/2728 (203.206.x.x/2728) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:20|302013|203.206.x.x|2920|EmailServerInside|443|Built inbound TCP connection 9525066 for INTERNET:203.206.x.x/2920 (203.206.x.x/2920) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:20|302013|203.206.x.x|2919|EmailServerInside|443|Built inbound TCP connection 9525059 for INTERNET:203.206.x.x/2919 (203.206.x.x/2919) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:21|302013|203.206.x.x|2922|EmailServerInside|443|Built inbound TCP connection 9525090 for INTERNET:203.206.x.x/2922 (203.206.x.x/2922) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:21|302013|203.206.x.x|2921|EmailServerInside|443|Built inbound TCP connection 9525082 for INTERNET:203.206.x.x/2921 (203.206.x.x/2921) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:21|302014|203.206.x.x|2919|EmailServerInside|443|Teardown TCP connection 9525059 for INTERNET:203.206.x.x/2919 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP Reset-O
6|Aug 17 2011|11:01:21|302014|203.206.x.x|2920|EmailServerInside|443|Teardown TCP connection 9525066 for INTERNET:203.206.x.x/2920 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|11:01:22|302014|203.206.x.x|2921|EmailServerInside|443|Teardown TCP connection 9525082 for INTERNET:203.206.x.x/2921 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|11:01:22|302014|203.206.x.x|2922|EmailServerInside|443|Teardown TCP connection 9525090 for INTERNET:203.206.x.x/2922 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP Reset-O
6|Aug 17 2011|11:01:28|302013|203.206.x.x|2923|EmailServerInside|443|Built inbound TCP connection 9525318 for INTERNET:203.206.x.x/2923 (203.206.x.x/2923) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:31|302013|203.206.x.x|2924|EmailServerInside|443|Built inbound TCP connection 9525380 for INTERNET:203.206.x.x/2924 (203.206.x.x/2924) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:32|302013|203.206.x.x|2925|EmailServerInside|443|Built inbound TCP connection 9525412 for INTERNET:203.206.x.x/2925 (203.206.x.x/2925) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:32|302014|203.206.x.x|2924|EmailServerInside|443|Teardown TCP connection 9525380 for INTERNET:203.206.x.x/2924 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4102 TCP FINs
6|Aug 17 2011|11:01:32|302014|203.206.x.x|2923|EmailServerInside|443|Teardown TCP connection 9525318 for INTERNET:203.206.x.x/2923 to LAN:EmailServerInside/443 duration 0:00:03 bytes 5418 TCP FINs
6|Aug 17 2011|11:01:33|302013|203.206.x.x|2926|EmailServerInside|443|Built inbound TCP connection 9525458 for INTERNET:203.206.x.x/2926 (203.206.x.x/2926) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:35|302014|203.206.x.x|2926|EmailServerInside|443|Teardown TCP connection 9525458 for INTERNET:203.206.x.x/2926 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4102 TCP FINs
6|Aug 17 2011|11:01:35|302014|203.206.x.x|2925|EmailServerInside|443|Teardown TCP connection 9525412 for INTERNET:203.206.x.x/2925 to LAN:EmailServerInside/443 duration 0:00:02 bytes 4038 TCP FINs
6|Aug 17 2011|11:01:46|302013|203.206.x.x|2928|EmailServerInside|443|Built inbound TCP connection 9525759 for INTERNET:203.206.x.x/2928 (203.206.x.x/2928) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:47|302013|203.206.x.x|2929|EmailServerInside|443|Built inbound TCP connection 9525778 for INTERNET:203.206.x.x/2929 (203.206.x.x/2929) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:49|302014|203.206.x.x|2929|EmailServerInside|443|Teardown TCP connection 9525778 for INTERNET:203.206.x.x/2929 to LAN:EmailServerInside/443 duration 0:00:02 bytes 4102 TCP FINs
6|Aug 17 2011|11:01:49|302014|203.206.x.x|2928|EmailServerInside|443|Teardown TCP connection 9525759 for INTERNET:203.206.x.x/2928 to LAN:EmailServerInside/443 duration 0:00:03 bytes 4038 TCP FINs
6|Aug 17 2011|11:01:50|302013|203.206.x.x|2936|EmailServerInside|443|Built inbound TCP connection 9525890 for INTERNET:203.206.x.x/2936 (203.206.x.x/2936) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:50|302013|203.206.x.x|2935|EmailServerInside|443|Built inbound TCP connection 9525876 for INTERNET:203.206.x.x/2935 (203.206.x.x/2935) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:01:51|302014|203.206.x.x|2936|EmailServerInside|443|Teardown TCP connection 9525890 for INTERNET:203.206.x.x/2936 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|11:01:51|302014|203.206.x.x|2935|EmailServerInside|443|Teardown TCP connection 9525876 for INTERNET:203.206.x.x/2935 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4038 TCP FINs
6|Aug 17 2011|11:02:02|302013|203.206.x.x|2939|EmailServerInside|443|Built inbound TCP connection 9526250 for INTERNET:203.206.x.x/2939 (203.206.x.x/2939) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:02:03|302014|203.206.x.x|2943|EmailServerInside|443|Teardown TCP connection 9526278 for INTERNET:203.206.x.x/2943 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|11:02:03|302013|203.206.x.x|2942|EmailServerInside|443|Built inbound TCP connection 9526272 for INTERNET:203.206.x.x/2942 (203.206.x.x/2942) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:02:03|302013|203.206.x.x|2943|EmailServerInside|443|Built inbound TCP connection 9526278 for INTERNET:203.206.x.x/2943 (203.206.x.x/2943) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:02:03|302014|203.206.x.x|2942|EmailServerInside|443|Teardown TCP connection 9526272 for INTERNET:203.206.x.x/2942 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4038 TCP FINs
6|Aug 17 2011|11:02:03|302014|203.206.x.x|2941|EmailServerInside|443|Teardown TCP connection 9526255 for INTERNET:203.206.x.x/2941 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4102 TCP FINs
6|Aug 17 2011|11:02:03|302014|203.206.x.x|2939|EmailServerInside|443|Teardown TCP connection 9526250 for INTERNET:203.206.x.x/2939 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4158 TCP FINs
6|Aug 17 2011|11:02:03|302013|203.206.x.x|2941|EmailServerInside|443|Built inbound TCP connection 9526255 for INTERNET:203.206.x.x/2941 (203.206.x.x/2941) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:04:13|302013|203.206.x.x|2974|EmailServerInside|443|Built inbound TCP connection 9530126 for INTERNET:203.206.x.x/2974 (203.206.x.x/2974) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:04:13|302013|203.206.x.x|2973|EmailServerInside|443|Built inbound TCP connection 9530123 for INTERNET:203.206.x.x/2973 (203.206.x.x/2973) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:04:16|302014|203.206.x.x|2979|EmailServerInside|443|Teardown TCP connection 9530221 for INTERNET:203.206.x.x/2979 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4070 TCP FINs
6|Aug 17 2011|11:04:16|302014|203.206.x.x|2980|EmailServerInside|443|Teardown TCP connection 9530229 for INTERNET:203.206.x.x/2980 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4304 TCP FINs
6|Aug 17 2011|11:04:16|302013|203.206.x.x|2979|EmailServerInside|443|Built inbound TCP connection 9530221 for INTERNET:203.206.x.x/2979 (203.206.x.x/2979) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:04:16|302013|203.206.x.x|2980|EmailServerInside|443|Built inbound TCP connection 9530229 for INTERNET:203.206.x.x/2980 (203.206.x.x/2980) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:04:16|302014|203.206.x.x|2974|EmailServerInside|443|Teardown TCP connection 9530126 for INTERNET:203.206.x.x/2974 to LAN:EmailServerInside/443 duration 0:00:02 bytes 5188 TCP Reset-O
6|Aug 17 2011|11:04:16|302014|203.206.x.x|2973|EmailServerInside|443|Teardown TCP connection 9530123 for INTERNET:203.206.x.x/2973 to LAN:EmailServerInside/443 duration 0:00:02 bytes 5146 TCP Reset-O
6|Aug 17 2011|11:04:18|302013|203.206.x.x|2982|EmailServerInside|443|Built inbound TCP connection 9530298 for INTERNET:203.206.x.x/2982 (203.206.x.x/2982) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:04:18|302013|203.206.x.x|2981|EmailServerInside|443|Built inbound TCP connection 9530292 for INTERNET:203.206.x.x/2981 (203.206.x.x/2981) to LAN:EmailServerInside/443 (EmailServerOutside/443)
6|Aug 17 2011|11:04:19|302014|203.206.x.x|2981|EmailServerInside|443|Teardown TCP connection 9530292 for INTERNET:203.206.x.x/2981 to LAN:EmailServerInside/443 duration 0:00:01 bytes 4070 TCP FINs
6|Aug 17 2011|11:04:19|302014|203.206.x.x|2982|EmailServerInside|443|Teardown TCP connection 9530298 for INTERNET:203.206.x.x/2982 to LAN:EmailServerInside/443 duration 0:00:00 bytes 4630 TCP FINs

Regards....

Inspect: http BlockUrlPolicy, packet 10916492, drop 4211, reset-drop 2291

Can you turn off http inspection temporarily and test again?

Hi Lcaruso,

I have already tried it and that didnt make any difference.

Regards,

The RESET-O are generated when the SERVER is not listening on that TCP port.

The RESET-I  are generated when the client tores down the connection to the server.

Both are Informational level logging , which is nothing but what's going with the traffic from your firewall , normally this is set up to error level but then again it depends upon your company preference.

As far why the clients are not able to down load large files could  be associated with the http block url policy. But since you said that turrning off http inspection didn't help  than I would like to know that does the server lets you download the big files when you are inside the Firewall in the same subnet as the server + different subnet if any but inside the firewall ?

Manish

Hi Manish,

Thanks for taking the time to reply, Yes turning off the http block url policy doesnt make any different, and the large email attachment issue is only face by the external clients who are coming via the internet. These clients use Outlook anywhere and OWA (https 443) to access emails. Internal clients do not have any issues and there email continue to work as normal.

Regards...

Hi,

Sorry for the late reply but for some reason I am not getting emails when from cisco when someone replies to the Post. Anyway, Can you please explain what error do you get when sending attachment of larger size ? Is it something like "Attachment size exceeds the limit" or there is no error and email never reaches the other end.

Can you also post the configuration of the service policies that you have ?

Also, post the error message send back by the Exchange server if any.

Thanks

Manish

Hi Manish,

As i initially described, problem is not with sending large email, its when the user is connected to Microsoft Exchange over 443 (RPC over HTTPS) and they have received an email with large attachment (in this case over 1 MB). Their outlook just shows updating inbox, and if they try and download that email through OWA response is similar where its start downloading the attachment and then slows down to 0bytes per second.

Service policy output is already been provided in the earlier post, no errors in exchange event log.

Thanks..

Can you turn off all inspection and test again?

or there's this...

Test attachement problem from a known ip address externally.

You'll need three simultaneous captures:

1. capture on outside interface from/to any from/to public ip of exchange

2. capture on inside interface from/to any from/to private ip of exchange

3. capture on the exchange server with wireshark latest version

There's a method to download them as wireshark files from the ASA. 

Once you have those three simultaneous captures, you'll be able to trace each

packet's request and response. For example, a client packet hits the outside

interface of the ASA, then is seen on the inside interface, then is seen hitting 

the server. Then, the server is seen replying to that packet. Then that reply hits

the inside interface of the ASA, then that same packet is seen exiting the

outside interface of the ASA.

If one packet is dropped in this, you will see where it happened and you will

confirm where the problem exists. If resets are involved you will see those.

Hi,

Are these users connecting to the OWA/outlook over some kind of remote VPN ?

Manish

I think we shouldn;t drag this any more , Can you revert back to the Older Code ? If yes than :-

1> If it starts working after you switch back to the older code than Open a ticket with Cisco.

2> If it still doesn't work than You need to look further towards the Exchange server and check if something got changed or updated etc recently.

Manish

Guys,

I found the problem, I had a IM block policy on the LAN interface, as soon as i removed that policy, issue was resolved, here is the part of the service policy config posted earlier, which was causing the issue.

Interface LAN:

Service-policy: IM

Class-map: imblock

Inspect: im impolicy, packet 75996195, drop 4, reset-drop 0

It still doesnt make sense to me why would this policy create such problem? but anyway

I thank you all for your help.

Regards...

Never hurts to turn off all inspections in such a case. Quick and easy to test.

Glad you got it resolved.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card