Hi guys,
I have ASA 5515 running at 9.6.(3)1.
In logs I noticed a huge amount of very strange records.
Duplicate TCP SYN from INSIDE: A /52565 to INSIDE: B /3389 with different initial sequence number
Where IP "A" is Windows VM.
Even when I shutdown VM with ip "A" I still see above logs.
VM stays in ESX. Both ESX and ASA are connected to FEX ports.
Does somebody have some ideas what is going on and how such "fake" addresses are being generated?
I tried to update OS on asa, no results.
Thanks in advance.