cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
184
Views
0
Helpful
1
Replies

Firewall ASA can't track the operating state of a session

inobody135
Level 1
Level 1

Hi all and Merry Christmas :)

i have a problem configuring my firewall the scenario is i have couple of machines that contact a syslog server via UDP outside the network the problem when the server respond it responds in an other source port when it comes to my firewall he drop the packets because he couldn't track the session my machines keep sending the data over and over, can you help me to configure my firewall to allow that thank you very much for helping.

1 Accepted Solution

Accepted Solutions

Ajay Saini
Level 7
Level 7

If the port is being changed, the only solution is to open corresponding port(s) for the traffic coming from syslog server to machines using access-list. For udp connection, there is no state, hence the only way ASA can keep a track of connection is by tracking the ip address and port number. 

In this case, please open an access list for inbound connection as well and it should work.

HTH

-
AJ

View solution in original post

1 Reply 1

Ajay Saini
Level 7
Level 7

If the port is being changed, the only solution is to open corresponding port(s) for the traffic coming from syslog server to machines using access-list. For udp connection, there is no state, hence the only way ASA can keep a track of connection is by tracking the ip address and port number. 

In this case, please open an access list for inbound connection as well and it should work.

HTH

-
AJ

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card