cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


124
Views
0
Helpful
1
Replies
Beginner

Deny TCP connection

%ASA-6-106015: Deny TCP (no connection) from xx.xx.xx.xx/sp to yy.yy.yy.yy/dp flags RST on interface inside

Hi, I am getting the above message on syslog.

Wat cud be the potential issue.

Is it with my ASA or with the destination server?

There is an alllow rule in the ASA(inside to any) on 80/443.

1 REPLY 1
Highlighted
VIP Advisor

Re: Deny TCP connection

106015

Error Message %ASA-6-106015: Deny TCP (no connection) from IP_address /port to IP_address /port flags tcp_flags on interface interface_name.

Explanation The ASA discarded a TCP packet that has no associated connection in the ASA connection table. The ASA looks for a SYN flag in the packet, which indicates a request to establish a new connection. If the SYN flag is not set, and there is no existing connection, the ASA discards the packet.

Recommended Action None required unless the ASA receives a large volume of these invalid TCP packets. If this is the case, trace the packets to the source and determine the reason these packets were sent.

BB
*** Rate All Helpful Responses ***