09-17-2015 09:01 AM - edited 03-11-2019 11:36 PM
ASA 5520
Logs are flooded with multiple Deny TCP entries on interface inside. From internal user IPs to unknown outside public IPs:
Deny TCP (no connection) from 172.26.x.x/63422 to 216.58.216.98/443 flags RST ACK on interface inside
Deny TCP (no connection) from 172.26.x.x/62898 to 104.16.27.235/80 flags RST ACK on interface inside
Deny TCP (no connection) from 172.26.x.x/62315 to 208.111.168.7/80 flags RST ACK on interface inside
Looking to see if these are normal or something to look into? Let me know if there's anything else I can post