cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1675
Views
0
Helpful
11
Replies

ASA not passing traffic to only one website.

brian.neil
Level 1
Level 1

Since replacing a dead ASA 5505 w/another ASA and running the same image and config the user is having issues getting to one website and only one website. Packet tracer and logs show a connection opening up but then closes in about 12-14 seconds. The website shows no traffic from our IP address. We have rebooted and we updated the firmware from 8.4(3) to 8.4(7) 23 and have the same issue.

11 Replies 11

Pranay Prasoon
Level 3
Level 3

Is it an outbound or inbound connection? What does log say, please share logs and running-config as attachment along with IP address of user  with us?

Ok I uploaded the packet capture, logs and config. The only site we are having issues with is a public site external to this ASA.

 I don't see attachment.

How about now?

Teardown TCP connection 53254 for outside:199.204.136.40/443 to inside:172.16.2.65/49455 duration 0:00:30 bytes 0 SYN Timeout

 

The connection is being closed because of SYN timeout means ASA is seeing SYN going to server while SYN/ACK is not coming back from sever. Now since all other sites are working and problem is only with this website. I guess it might be because the IP address traffic is reaching to the server might be blocked because of some malicious transaction. As you said it is working fine for a directly connected machine so did you try to verify whether outside IP address of ASA (since Ip address is being assigned to outside interface through DHCP ) and machine were same. If not I guess we can try reloading the cable modem from ISP.

Yes, the onsite technician who did the testing said the IP address he pulled on the PC was the same as the ASA. We always reboot the cable modem when changing the device that is being connected to it. In fact, we had the cable provider replace the modem the day of that test as there was an different issue with the older modem.

well looking at logs, I don't find ASA is dropping packet. However, captures on inside and outside interface will be helpful.

 

SYN packet has nothing much which can prompt server not to reply it.

I saw reference on older versions of ASA with this problem where it had to do with MSS timers.

I am planning to go onsite and erase the config and rebuild. I will also take another ASA with me just incase.  

 

okay..However in that case server should have sent a reset packet. But it doesn't seem to be responding.

Hozaifa Samad
Level 1
Level 1

Even the new ASA has the same code & config, MAC address is different. To find out if the issue is the ASA or not, you can do capture on the inside & outside and make sure you see traffic leaving ASA (outside). If you do see traffic leaving and nothing is coming back, then it's not ASA issue.

 

If you find out the issue is ASA, please paste the config along with IP addresses information.

Prior to you response we bypassed the ASA and plugged directly into the ISP cable modem and was able to access this website without any issues, Plugged ASA back in and issue returned. I did share files you had requested but I will need to go onsite to get the capture.

Review Cisco Networking for a $25 gift card