cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
288
Views
0
Helpful
1
Replies

log message problem

walidboudich
Level 1
Level 1

hello,

my PIX had reported the following message:

Dec 22 08:15:11 192.168.47.254 %PIX-6-106015: Deny TCP (no connection) from 10.23.18.102/1035 to 192.168.50.214/80 flags RST on interface outside

i can't understand the (no connection) message

can you give me some help

thanks

1 Reply 1

phil.benn
Level 1
Level 1

hi,

i would expect that it's because your source host (10.23.18.102) is trying to send a reset (RST) to the host the other side of the pix. if the pix doesn't have a connection listed in its state table, it won't expect the RST and will thus report 'no connection'. it's probably nothing to worry about, i notice the d-port is 80, web browsers sometimes send RSTs back to webservers to close connections quickly; instead of tearing them down properly.