12-10-2019 11:36 PM
Hello,
I am facing an interesting situation where a Firepower with the ASA module is passing a part of a communication only. This is very strange for me and I have no idea what can cause this issue. The situation is that we have let's say a server - client model, where a client is asking for a data from the server over a port TCP/2000. Client (10.248.224.9) is behind the ingress interface of the capture and server (10.248.187.36) is behind the egress interface of the capture. Client is connected wired, server wireless. So the client initiates a 3-way handshake which is successful and can be seen on both interfaces (ingress and egress). The client initiates a connection many times using random different source ports. Then a server continuously sends a data over the tcp port 2000, client acknowledges that. Most of the packets sent by the server are 200 bytes of data with a PSH flag set. It can be seen that a firewall merges this and sends it as bigger packets - what i understand is due to the PSH flag and is to effectively use a tcp window.
What the strange is, that on the ingress interface, there is a lot of communication missing. There are connections where only a 3-way handshake and reset can be seen, as well as connections where only a part of data is present. On the egress interface, all the communication can be seen - even the acks from the client which is acknowledging a traffic which was not present on the ingress interface.
It seems this is application specific, but does anyone have an idea what can the root cause be?
I am attaching captures as well.
Many thanks for any advice.
Martin
12-11-2019 09:48 PM
Is there any chance the ASA is affecting a traffic because the TCP 2000 is a public port for SCCP? Absolutely need to test it..
12-11-2019 10:06 PM
Hello,
I saw this problem happen before and the reason is because port 2000 is reserved, try change the server port to other port instead 2000.
Cheers,
12-11-2019 10:48 PM
Yeah, I have already contacted vendor to test another port. Thanks.
12-12-2019 01:33 AM
Don't forget to come with resolution in case solve and rate the helpful post!
Cheers
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide