cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
490
Views
0
Helpful
2
Replies

Trouble with hairpinning

James Dykes
Level 1
Level 1

I am trying to set up a hairpinning configuration for a client, wherein they have hardcoded their external IP address in their application for SQL access. From one of their servers the hairpinning works somewhat - a connection is established, but there are FIN ACK timeouts trying to close the connection. From other servers, I'm not even able to get that far - the connection gets a SYN timeout.

My config is attached with the externals redacted. What am I missing?

2 Replies 2

lcambron
Level 3
Level 3

James,

We need more information about the packet flow.

What are the source and destination addresses, is the connection coming from inside and destined to the inside as well?

Regards,

Felipe.

n_schloemer
Level 1
Level 1

James,

Have you created a tcp-state-bypass policy-map which matches your traffic flows?  We had a similar issue with load-balanced edge Lync servers and saw similar TCP debug returns.  Below is some information you may want to look at.

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_tcpstatebypass.pdf

Thanks,

Nick

Review Cisco Networking for a $25 gift card