cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
875
Views
0
Helpful
5
Replies

TCP Issue

Grizzelz
Level 1
Level 1

Hi Cisco Team,

I know the answer to this question but reaching out as not sure what else the issue can be.

We have a customer who uses scanner guns on the enviroment. from a packet capture say the gun is y.y.y.y and the destination is x.x.x.x on port 4003 we never ever receive a TCP FIN coming back from x.x.x.x.

Now we took the same capture and looked at other ports and those connections from a TCP point of view work fine, I am very sure this is a remote side isssue, but if the customer uses these devices at home or a device past the External Firewall it works fine.

To rule out the firewall we setup a permit IP rule for y.y.y.y to talk with x.x.x.x this still did not sort the issue, we also setup SFR bypass on the firepower module for y.y.y.y to any again did not resolve the issue, and tbh I would not have expected it to.

Does anyone have any other ideas something maybe i have missed.

 

70: 15:45:49.512882 x.x.x.x.4003 > y.y.y.y.41470: . 2557994275:2557995642(1367) ack 3980043660 win 190 <nop,nop,timestamp 1340342376 2456367870>
71: 15:45:49.512897 x.x.x.x.4003 > y.y.y.y.41470: P 2557995642:2557996922(1280) ack 3980043660 win 190 <nop,nop,timestamp 1340342376 2456367870>
72: 15:45:49.515003 y.y.y.y.41470 > x.x.x.x.4003: . ack 2557995642 win 141 <nop,nop,timestamp 2456368684 1340342376>
73: 15:45:49.550630 y.y.y.y.41470 > x.x.x.x.4003: . ack 2557996922 win 147 <nop,nop,timestamp 2456368720 1340342376>
74: 15:45:49.568314 y.y.y.y.41470 > x.x.x.x.4003: P 3980043660:3980045027(1367) ack 2557996922 win 147 <nop,nop,timestamp 2456368738 1340342376>
75: 15:45:49.568436 y.y.y.y.41470 > x.x.x.x.4003: P 3980045027:3980045450(423) ack 2557996922 win 147 <nop,nop,timestamp 2456368738 1340342376>
76: 15:45:49.582214 x.x.x.x.4003 > y.y.y.y.41470: . ack 3980045450 win 271 <nop,nop,timestamp 1340342446 2456368738>
77: 15:45:49.586898 x.x.x.x.4003 > y.y.y.y.41470: P 2557996922:2557997328(406) ack 3980045450 win 271 <nop,nop,timestamp 1340342450 2456368738>
78: 15:45:49.588409 y.y.y.y.41470 > x.x.x.x.4003: . ack 2557997328 win 152 <nop,nop,timestamp 2456368758 1340342450>
79: 15:45:49.633786 y.y.y.y.41470 > x.x.x.x.4003: P 3980045450:3980046817(1367) ack 2557997328 win 152 <nop,nop,timestamp 2456368803 1340342450>
80: 15:45:49.633893 y.y.y.y.41470 > x.x.x.x.4003: P 3980046817:3980047240(

5 Replies 5