cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
367
Views
0
Helpful
2
Replies

ASA reset packet

sameerj1212
Level 1
Level 1

Hello All,

If i am trying to access FW separated server and im getting reset packet on FW, who generates it.

As in destination server generates the reset packet or FW itself generates it.

2 Replies 2

Collin Clark
VIP Alumni
VIP Alumni

Either can generate it, it depends on the configuration. You can do a packet capture on either the server or the ASA to determine which device is actually dropping it.

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118097-configure-asa-00.html

Ajay Saini
Level 7
Level 7

Both are capable of sending reset packets are depending on circumstances, each can send one.

The best way to find out who is sending reset is to take capture on either the destination server nic through wireshark or take capture on ingress and egress interface of the firewall. 

If you take capture on the firewall and see the reset only on egress and not on ingress interface, then we are sure that firewall generated the same. Ideally, if firewall generates the reset packet, it sends one to both ends.

HTH
AJ

Review Cisco Networking for a $25 gift card