cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
387
Views
0
Helpful
2
Replies

TCP resets on PIX to CSS

bclarkson
Level 1
Level 1

On new install, workstation accesses VIP on CSS with 3 web servers. With PIX in between, got continuous Built inbound, followed by Teardown TCP....Reset-O. Other non CSS connections were working fine. Is there anything special or considerations for PIXes dealing with CSS's? Timers?

2 Replies 2

davecs
Level 1
Level 1

hi.

how have you setup your CSS? in a ProxyIP or Direct Server fetch?

ie does the CSS change source IP to itself or does it leave the packet as is?

the PIX should just see it as regular TCP traffic!

Is the health checking ok?

ddawson
Level 1
Level 1

The "Reset-O" inthe Teardown message is a big clue. It means the reset came from the outside, which is the workstation. I'm not aware of any special PIX configs needed for working with a CSS, so you may have to do some packet captures to determine why the workstation is unhappy with the connection. I find "ethereal" to be especially useful for this, since you can run it directly on the client machine and sniff your own packets.

Review Cisco Networking for a $25 gift card