cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
441
Views
0
Helpful
1
Replies

asa5505v8 tcp syn denied on inside

krjohnson
Level 1
Level 1

"Inbound TCP connection denied from 1.4.19.244/1635 to 1.4.20.212/4001 flags SYN on interface inside"

The vlan on the inside interface (vlan19) also needs access to systems on vlan20 so we have a static route on the asa that points to a router that also sits on vlan19. I can ping the two vlans from the asa's inside interface but I'm not sure why the above error occurs or how to stop it.

1 Reply 1

Jon Marshall
Hall of Fame
Hall of Fame

Keith

So is the default-gateway for clients on vlan 19 the ASA inside interface ?.

If so have you added this to your config -

asa(config)# same-security-traffic permit intra-interface

if you don't have that in your config traffic will not be allowed back out the same interface it arrived on to get to it's destination.

Jon

Review Cisco Networking for a $25 gift card