10-11-2004 10:12 PM - edited 02-20-2020 11:40 PM
On new install, workstation accesses VIP on CSS with 3 web servers. With PIX in between, got continuous Built inbound, followed by Teardown TCP....Reset-O. Other non CSS connections were working fine. Is there anything special or considerations for PIXes dealing with CSS's? Timers?
10-13-2004 08:10 PM
hi.
how have you setup your CSS? in a ProxyIP or Direct Server fetch?
ie does the CSS change source IP to itself or does it leave the packet as is?
the PIX should just see it as regular TCP traffic!
Is the health checking ok?
10-14-2004 08:10 AM
The "Reset-O" inthe Teardown message is a big clue. It means the reset came from the outside, which is the workstation. I'm not aware of any special PIX configs needed for working with a CSS, so you may have to do some packet captures to determine why the workstation is unhappy with the connection. I find "ethereal" to be especially useful for this, since you can run it directly on the client machine and sniff your own packets.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide