10-08-2007 06:55 AM - edited 03-11-2019 04:22 AM
I'm seeing a lot of events in our ASA logs for 106001 relating to external source TCP (port 80) connections being denied inbound to our PAT address. The sources are all valid web sites which users are accessing. If a source inside connects to a website outside, surely the return traffic will be permitted without needing any extra ACLs?
10-12-2007 09:55 AM
This is a connection-related message. This message occurs when an attempt to connect to an inside address is denied by your security policy. Possible tcp_flags values correspond to the flags in the TCP header that were present when the connection was denied. Indeed that means the conn table removed the connection. Such kind of messages are usually generated due to bad server kernel implementation.
10-14-2007 11:14 PM
So the websites generating these messages are at fault rather than anything wrong with our configuration or something malicious?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide