cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
431
Views
0
Helpful
2
Replies

Inbound TCP connection denied from 192.168.1.x to 192.168.1.y flags SYN on interface

trylvis123
Level 1
Level 1

Hi,

We reviece some logging alerts from our Cisco ASA firewall with the message:

"Inbound TCP connection denied from 192.168.1.x/x to 192.168.1.y/y flags SYN interface intX.

The two hosts is on the same subnet, and I'm wondering why this traffic is blocked.

I've run a packet tracer, which also results in a block. We have a bottom-ACL on this interface which deny traffic from "any" to "any".

Under "Device Setup" -> "Interfaces", "Enable traffic between two or more hosts connected to the same interface" is not enabled. 

Thanks!

2 Replies 2

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

Yes you need to enable traffic between two or more hosts connected to the same interface.

You can use a CLI command to enable this as well:

same-security-traffic permit intra-interface

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Thank you for the reply,

Can there be any problems by turning on this feature? We do not use these for VPN.

Review Cisco Networking for a $25 gift card