Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Best practices:Create an acl and apply it on your firewalls inside interface. Here are sample how to do this specially for the SASSER worm:Access-list inside deny tcp any any eq 445Access-list inside deny tcp any any eq 5554Access-list inside deny t...
I had the same problem before, however, you did not give much detail in your post. - check pfs make sure they policies are matching at both Pixs- make sure the SA life time are matching on both Pixs !hope this helps.