02-26-2019 01:52 AM - edited 02-21-2020 08:51 AM
Hi
I attempted an upgrade of a ASA 5585-X cluster from v.9.1(2) to 9.10(1). The actual upgrade was fine but then we noticed that a large number of servers behind the firewall could not be accessed. This seemed to be intermittent, as some were ok others were not, even if they were on the same vlan.
Unfortunately, I could not do much troubleshooting, as this affected some key services, so I had to back out and reboot the cluster on v.9.1(2). As soon as we downgraded, performance was immediately back to normal.
However, looking through our syslogs, I noticed that during the affected period, I have a large number, i.e. at least 500 per minute, of "%ASA-4-419002: Duplicate TCP SYN". During normal operations, before and since the upgrade, I do not see any of these messages.
I'm still researching this but a lot of articles about this error mention spoofing, possible attacks or a routing problem. The cluster is our DMZ firewall, so has internal connections only. If I had some dodgy device on our network or we had a routing issue, surely I would see these messages all the time but I don't.
Has anyone upgraded to v.9.10 yet? Has anyone seen this issue with an upgrade?
Thanks
Roy
03-25-2019 07:44 AM
04-01-2019 06:42 PM
Hi roysm
it can be just a packet generator, not even a machine with that IP address.
The source and destination interface are the same and this is the default that has security level 100.
I could check and if you need to send in private, please.
Best Regards,
Josiane
Twitter :@securegirlninja
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide