04-07-2015
10:06 AM
- last edited on
03-25-2019
05:55 PM
by
ciscomoderator
Since replacing a dead ASA 5505 w/another ASA and running the same image and config the user is having issues getting to one website and only one website. Packet tracer and logs show a connection opening up but then closes in about 12-14 seconds. The website shows no traffic from our IP address. We have rebooted and we updated the firmware from 8.4(3) to 8.4(7) 23 and have the same issue.
04-07-2015 01:32 PM
Is it an outbound or inbound connection? What does log say, please share logs and running-config as attachment along with IP address of user with us?
04-07-2015 08:25 PM
Ok I uploaded the packet capture, logs and config. The only site we are having issues with is a public site external to this ASA.
04-07-2015 09:06 PM
I don't see attachment.
04-07-2015 09:28 PM
04-07-2015 09:50 PM
Teardown TCP connection 53254 for outside:199.204.136.40/443 to inside:172.16.2.65/49455 duration 0:00:30 bytes 0 SYN Timeout
The connection is being closed because of SYN timeout means ASA is seeing SYN going to server while SYN/ACK is not coming back from sever. Now since all other sites are working and problem is only with this website. I guess it might be because the IP address traffic is reaching to the server might be blocked because of some malicious transaction. As you said it is working fine for a directly connected machine so did you try to verify whether outside IP address of ASA (since Ip address is being assigned to outside interface through DHCP ) and machine were same. If not I guess we can try reloading the cable modem from ISP.
04-08-2015 05:57 AM
Yes, the onsite technician who did the testing said the IP address he pulled on the PC was the same as the ASA. We always reboot the cable modem when changing the device that is being connected to it. In fact, we had the cable provider replace the modem the day of that test as there was an different issue with the older modem.
04-08-2015 08:04 AM
well looking at logs, I don't find ASA is dropping packet. However, captures on inside and outside interface will be helpful.
SYN packet has nothing much which can prompt server not to reply it.
04-08-2015 08:19 AM
I saw reference on older versions of ASA with this problem where it had to do with MSS timers.
I am planning to go onsite and erase the config and rebuild. I will also take another ASA with me just incase.
04-08-2015 08:38 AM
okay..However in that case server should have sent a reset packet. But it doesn't seem to be responding.
04-07-2015 01:47 PM
Even the new ASA has the same code & config, MAC address is different. To find out if the issue is the ASA or not, you can do capture on the inside & outside and make sure you see traffic leaving ASA (outside). If you do see traffic leaving and nothing is coming back, then it's not ASA issue.
If you find out the issue is ASA, please paste the config along with IP addresses information.
04-07-2015 08:30 PM
Prior to you response we bypassed the ASA and plugged directly into the ISP cable modem and was able to access this website without any issues, Plugged ASA back in and issue returned. I did share files you had requested but I will need to go onsite to get the capture.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide