cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
297
Views
0
Helpful
3
Replies

Problem with Webserver on port 443

osn
Level 1
Level 1

1: 08:22:02.155616 802.1Q vlan#1206 P0 10.86.19.165.57007 > 172.16.20.29.443: S 2884629256:2884629256(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
2: 08:22:02.156638 802.1Q vlan#1206 P0 10.86.19.165.57008 > 172.16.20.29.443: S 1672063593:1672063593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
3: 08:22:02.413766 802.1Q vlan#1206 P0 10.86.19.165.57009 > 172.16.20.29.443: S 2808015046:2808015046(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
4: 08:22:03.158698 802.1Q vlan#1206 P0 10.86.19.165.57007 > 172.16.20.29.443: S 2884629256:2884629256(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
5: 08:22:03.164908 802.1Q vlan#1206 P0 10.86.19.165.57008 > 172.16.20.29.443: S 1672063593:1672063593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
6: 08:22:03.424584 802.1Q vlan#1206 P0 10.86.19.165.57009 > 172.16.20.29.443: S 2808015046:2808015046(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
7: 08:22:05.159629 802.1Q vlan#1206 P0 10.86.19.165.57007 > 172.16.20.29.443: S 2884629256:2884629256(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
8: 08:22:05.424736 802.1Q vlan#1206 P0 10.86.19.165.57009 > 172.16.20.29.443: S 2808015046:2808015046(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
9: 08:22:05.466604 802.1Q vlan#1206 P0 10.86.19.165.57008 > 172.16.20.29.443: S 1672063593:1672063593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
10: 08:22:09.173468 802.1Q vlan#1206 P0 10.86.19.165.57007 > 172.16.20.29.443: S 2884629256:2884629256(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
11: 08:22:09.189077 802.1Q vlan#1206 P0 10.86.19.165.57008 > 172.16.20.29.443: S 1672063593:1672063593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
12: 08:22:09.440178 802.1Q vlan#1206 P0 10.86.19.165.57009 > 172.16.20.29.443: S 2808015046:2808015046(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
13: 08:22:17.183324 802.1Q vlan#1206 P0 10.86.19.165.57007 > 172.16.20.29.443: S 2884629256:2884629256(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
14: 08:22:17.199055 802.1Q vlan#1206 P0 10.86.19.165.57008 > 172.16.20.29.443: S 1672063593:1672063593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
15: 08:22:17.448585 802.1Q vlan#1206 P0 10.86.19.165.57009 > 172.16.20.29.443: S 2808015046:2808015046(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
16: 08:23:04.460028 802.1Q vlan#1206 P0 10.86.19.165.57025 > 172.16.20.29.443: S 49800722:49800722(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
17: 08:23:04.467672 802.1Q vlan#1206 P0 10.86.19.165.57026 > 172.16.20.29.443: S 2351361593:2351361593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
18: 08:23:04.719643 802.1Q vlan#1206 P0 10.86.19.165.57027 > 172.16.20.29.443: S 2095560515:2095560515(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
19: 08:23:05.464209 802.1Q vlan#1206 P0 10.86.19.165.57025 > 172.16.20.29.443: S 49800722:49800722(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
20: 08:23:05.485860 802.1Q vlan#1206 P0 10.86.19.165.57026 > 172.16.20.29.443: S 2351361593:2351361593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
21: 08:23:05.730583 802.1Q vlan#1206 P0 10.86.19.165.57027 > 172.16.20.29.443: S 2095560515:2095560515(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
22: 08:23:06.957881 802.1Q vlan#1206 P0 10.86.19.165.57029 > 172.16.20.29.443: S 3034751535:3034751535(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
23: 08:23:06.959636 802.1Q vlan#1206 P0 10.86.19.165.57028 > 172.16.20.29.443: S 422972133:422972133(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
24: 08:23:07.230365 802.1Q vlan#1206 P0 10.86.19.165.57030 > 172.16.20.29.443: S 4092544854:4092544854(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
25: 08:23:07.476736 802.1Q vlan#1206 P0 10.86.19.165.57025 > 172.16.20.29.443: S 49800722:49800722(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
26: 08:23:07.492711 802.1Q vlan#1206 P0 10.86.19.165.57026 > 172.16.20.29.443: S 2351361593:2351361593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
27: 08:23:07.749793 802.1Q vlan#1206 P0 10.86.19.165.57027 > 172.16.20.29.443: S 2095560515:2095560515(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
28: 08:23:07.963054 802.1Q vlan#1206 P0 10.86.19.165.57029 > 172.16.20.29.443: S 3034751535:3034751535(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
29: 08:23:07.964320 802.1Q vlan#1206 P0 10.86.19.165.57028 > 172.16.20.29.443: S 422972133:422972133(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
30: 08:23:08.236682 802.1Q vlan#1206 P0 10.86.19.165.57030 > 172.16.20.29.443: S 4092544854:4092544854(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
31: 08:23:09.973612 802.1Q vlan#1206 P0 10.86.19.165.57029 > 172.16.20.29.443: S 3034751535:3034751535(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
32: 08:23:09.985636 802.1Q vlan#1206 P0 10.86.19.165.57028 > 172.16.20.29.443: S 422972133:422972133(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
33: 08:23:10.242892 802.1Q vlan#1206 P0 10.86.19.165.57030 > 172.16.20.29.443: S 4092544854:4092544854(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
34: 08:23:11.480413 802.1Q vlan#1206 P0 10.86.19.165.57025 > 172.16.20.29.443: S 49800722:49800722(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
35: 08:23:11.507221 802.1Q vlan#1206 P0 10.86.19.165.57026 > 172.16.20.29.443: S 2351361593:2351361593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
36: 08:23:11.747703 802.1Q vlan#1206 P0 10.86.19.165.57027 > 172.16.20.29.443: S 2095560515:2095560515(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
37: 08:23:13.980570 802.1Q vlan#1206 P0 10.86.19.165.57029 > 172.16.20.29.443: S 3034751535:3034751535(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
38: 08:23:14.290588 802.1Q vlan#1206 P0 10.86.19.165.57028 > 172.16.20.29.443: S 422972133:422972133(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
39: 08:23:14.303420 802.1Q vlan#1206 P0 10.86.19.165.57030 > 172.16.20.29.443: S 4092544854:4092544854(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
40: 08:23:19.494603 802.1Q vlan#1206 P0 10.86.19.165.57025 > 172.16.20.29.443: S 49800722:49800722(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
41: 08:23:19.518237 802.1Q vlan#1206 P0 10.86.19.165.57026 > 172.16.20.29.443: S 2351361593:2351361593(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
42: 08:23:19.760031 802.1Q vlan#1206 P0 10.86.19.165.57027 > 172.16.20.29.443: S 2095560515:2095560515(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
43: 08:23:21.989710 802.1Q vlan#1206 P0 10.86.19.165.57029 > 172.16.20.29.443: S 3034751535:3034751535(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
44: 08:23:22.169104 802.1Q vlan#1206 P0 10.86.19.165.57028 > 172.16.20.29.443: S 422972133:422972133(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>
45: 08:23:22.254579 802.1Q vlan#1206 P0 10.86.19.165.57030 > 172.16.20.29.443: S 4092544854:4092544854(0) win 64240 <mss 1250,nop,wscale 8,nop,nop,sackOK>

i get this result when i do a capture and it says allwoed in the FW (FMC with FTD) 

1 Accepted Solution

Accepted Solutions

@osn 

It seems like the webserver is not responding. Is the webserver itself allowing this traffic, perhaps a local firewall?

Does it have a route back to the source 10.86.19.165?

I assume there is no NAT in this scenario?

Please run packet-tracer from the CLI to simulate the traffic flow, provide the output for review.

You can also run system support firewall-engine-debug and apply a filter, then generate traffic, provide the output.

 

View solution in original post

3 Replies 3

@osn 

It seems like the webserver is not responding. Is the webserver itself allowing this traffic, perhaps a local firewall?

Does it have a route back to the source 10.86.19.165?

I assume there is no NAT in this scenario?

Please run packet-tracer from the CLI to simulate the traffic flow, provide the output for review.

You can also run system support firewall-engine-debug and apply a filter, then generate traffic, provide the output.

 

I guess it was on the server the service was not running.

Do a packet capture on the firewall interface closest to the server.  If you see packets leaving the interface but nothing in return then there is an issue with the server.  If you see no packets at all, then the next thing I would check is if it is being dropped in SNORT / IPS (perhaps allow the traffic in prefilter to be sure you are bypassing SNORT)

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card