cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1387
Views
0
Helpful
1
Replies

How does the PIX 515 with 6.0 code handle TCP resets from the outside?

albertsmith
Level 1
Level 1

I have a user that keeps getting disconnected while connected to and ICA server. I checked the PIX syslog and found the following:

Built outbound TCP connection 3463853 for faddr 12.33.114.144/1494 gaddr 209.227.21.3/58769 laddr 10.1.6.152/1370

Teardown TCP connection 3463853 faddr 12.33.114.144/1494 gaddr 209.227.21.3/58769 laddr

10.1.6.152/1370 duration 0:02:36 bytes 35340 (TCP Reset-O)

Does this mean that the PIX does not handle TCP resets from the ICA server

1 Reply 1

s-doyle
Level 3
Level 3

A TCP reset is a place to start when hijacking a TCP session. A reset from the outside the PIX figures is potentially a hijack attempt and will close the session. I would talk to Cisco about this in your environment. There must be something causing all these resets. Excessive traffic, collisions, etc.

Review Cisco Networking for a $25 gift card