cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


79
Views
0
Helpful
2
Replies
Beginner

ASA5550 TCP connection denied

cisco ASA5550 Inbound TCP connection denied from 172.XX.XXX.2/3314 to 172.16.XX.XX/XXX flags SYN  on interface inside

2 REPLIES 2
Highlighted
Beginner

Can you post a config, or at

Can you post a config, or at least the ACLs that you have for either of those networks?

You may need to enable logging on those particular ACLs in order for me/us to figure out why these are being denied.  

See this about turning logging on.  It will give your logs more information, including which ACL is denying these packets

 

http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/acl_logging.pdf

Hall of Fame Guru

Are both the source and

Are both the source and destination address downstream from your inside interface? If so, you need to have "same-security-traffic" enabled in your configuration. Reference