cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1384
Views
0
Helpful
3
Replies

Duplicate TCP SYN from INT X.X.X.X

fadimabrouk
Level 1
Level 1

Hiii guys,

do anybody can assist me in to fix the issue of the log i'm getting on my ASA firewall

:Duplicate TCP SYN from INT: (MY IP behind ASA) to Outside: (the remote server outside ASA) with differenet initial sequence number

i don't know why this comes even i can see the traffic is reaching the remote server??

please your urgent support is needed

thank you

Fadi

3 Replies 3

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Fadi,

The question here is why is the host sending incorrect tcp packets ( SYN packest) In this case you will need to work on the host first and see why is doing that. BUT if you want to solve this on the easiest and non-secure way you will need to configure a TCP state bypass rule so the ASA will no longer statefully inspect the TCP connections:

access-list test permit tcp host ip_host_behind_asa host outside_server

class-map test

match access-list test

policy-map global_policy

class test

set connection advanced-options tcp-state-bypass

Do rate all the helpful posts!!

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hello,

sounds to be a soultion, not secure but i will test it.

Thanx

it's working fine now :-)

Review Cisco Networking products for a $25 gift card