Refuse the TCP (no relation) dan disassembly TCP connection ON ASA 5510, HELP Please

IM currently implemented with AIP-SSM-10 ASA 5510 IPS and I have problem with ASA, with IPS feature currently disabled, I keep received complain blocked/idle the connection to the oracle server, using port 8000 host remote-office, I traced with syslog and message received from large number associated with the oracle server IP address.

the network diagram is a bit like this:

________ ________ _____________

| Oracle | switch | ASA 5510 |

| Server | | ___ |---| transparent |

-------- -------------

192.168.10.206 |

|

|

-------------

| ROUTER |

|___________|

|

________ -------------

| DISTANCE | ------ | Router |

| THE USER | -------------

----------

192.168.5.x

and the syslog message looks like:

302013: built inbound connection TCP 1662347 for OUTSIDE:192.168.5.52/1311 (192.168.5.52/1311) inside:192.168.10.206/8000 (192.168.10.206/8000)

302014: disassembly of the TCP connection 1662345 for OUTSIDE:192.168.5.52/1310 for inside:192.168.10.206/8000 duration 0: 00:00 542 bytes TCP fins

302013: built inbound connection TCP 1662345 for OUTSIDE:192.168.5.52/1310 (192.168.5.52/1310) inside:192.168.10.206/8000 (192.168.10.206/8000)

302014: disassembly of the TCP connection 1662343 for OUTSIDE:192.168.5.52/1309 for inside:192.168.10.206/8000 duration 0: 00:00 539 bytes TCP fins

302013: built inbound connection TCP 1662343 for OUTSIDE:192.168.5.52/1309 (192.168.5.52/1309) inside:192.168.10.206/8000 (192.168.10.206/8000)

106015: deny TCP 192.168.5.52/1302 to 192.168.10.206/8000 flags ACK END on the OUTSIDE interface (no link)

302014: disassembly of the TCP connection 1662338 for OUTSIDE:192.168.5.52/1308 for inside:192.168.10.206/8000 duration 0: 00:00 538 bytes TCP fins

106015: deny TCP 192.168.5.52/1301 to 192.168.10.206/8000 flags ACK END on the OUTSIDE interface (no link)

106015: deny TCP 192.168.5.52/1298 to 192.168.10.206/8000 flags ACK END on the OUTSIDE interface (no link)

106015: deny TCP 192.168.5.52/1303 to 192.168.10.206/8000 flags ACK END on the OUTSIDE interface (no link)

can someone help me, I'm completely stuck on this problem to cause...

Thank you.

7.1 (2), which contains the fix for it, is already posted at http://www.cisco.com/cgi-bin/tablebuild.pl/pix.

If the workaround works for you, however, and you don't touch any other problems, then I would probably recommend you just stay on this version, but I'll leave it up to you.

Tags: Cisco Security

Similar Questions

  • Good method to reset the tcp connection after timeout error

    I have an application that I build that communicates with a Modbus TCP device.  If a communication occurs error I wish I could reset it TCP communication.  What I have is a control that raises an event when pushed.  In this case, I have a sequence that closes first the tcp connection and then opens a new connection.  My application starts and works very well.  To test the reset function, I removed the ethernet cable from the camera and waited until a timeout occurs.  I plugged the cable reset back to and pushed my control. Sometimes the reset will take place, but most of the time I'll get a timeout in the TCP vi open error.  After that, the only way I can establish communications must leave my application, disable and then enable the network device.  Then, when I restart my application I have communication with my camera.

    Any help would be appreciated on how I should be reset my TCP connection.

    Thank you

    Terry

    Terry S of a. in writing:

    I've attached an example vi (LV10) that shows just the connection TCP and Reset.  An error occurs when you try to run the open in the event of reset tcp protocol.

    As writing that your code should be fine. There is nothing inherently wrong with it. However, depending on the device, you communicate with you can try to restore the connection too quickly once you have closed the connection. The device allows multiple connections to it and may require some time to clean up the things on his end after you close a connection. An experimental basis try wait little time between TCP and the TCP Open shut it down. If possible you can try using Wireshark to see what is happening on the network. It may be useful to diagnose what is happening.

  • Problem of test Signal before using the TCP connection

    Right now my application uses a SocketConnection TCP to communicate with a remote server.  It works fine, but I'm trying to make sure that my program can correctly handle the situation to move to an area with no coverage.

    When I run my application, if I uncheck the box "on the cover" for GSM and CDMA under Network properties, my app fine until it calls the OutputStreamWriter.write () function to send something on the socket connection.  I have it in a try/catch block, but it just seems to hang instead of throwing an exception.

    How can I check the signal before attempting to send data on the SocketConnection?

    To facilitate clear life upwards, here's the order of what happens:

    1 application starts on the cover.

    2 SocketConnection made successfully.

    3 OutputStreamWriter successfully SocketConnection.

    4. coverage is lost

    5 OutputStreamWriter.write () is called, but freezes instead of throwing an exception.

    The socket connection output stream write operations do not throw an exception when there is no coverage is the correct behavior. That's because on cellular networks the IP tunnel to the carrier (and therefore the TCP connections on this tunnel) survives loss of coverage. For example, if your application opens a connection TCP from a BlackBerry, then the BlackBerry loses coverage, then take cover, say, 1 minute later, the TCP connection opened by your application will continue works fine, unless intermediate network component or your server closes the connection due to inactivity.

  • Apple Watch: can I receive all messages from whatsapp on my Apple Watch, but not the Group whatsapp messages, don't know why... Help, please. Besides, my watch is custom in Spanish, but only answer messages Whatsapp understands English... someone kn

    I can receive all messages from whatsapp on my Apple Watch, but not the Group whatsapp messages, don't know why... Help, please.

    Besides, my watch is custom in Spanish, but only answer messages Whatsapp understands English... anyone know why? Thanks to you all!

    Hello

    To change the language for a response on your watch: Press answer > firmly press the screen > press on choose language > select Spanish.

  • I can't open all the Web sites in firefox(version 25), its long loading time, help please

    I can't open all the Web sites in firefox(version 25), its long loading time, help please

    Hello, normally these problems are caused by a security/firewall software which does not recognize and therefore blocks the new versions of firefox: solve connection problems to websites after Firefox update

  • My Windows XP Professional cannot update SP3 because of lack of PRO11. Or the MSI files and I have the original MS Office 2003 CD to locate its files. Help, please.

    My Windows XP Professional cannot update SP3 because of lack of PRO11. Or the MSI files and I have the original MS Office 2003 CD to locate its files.  Help, please.

    Hello

    1. when exactly you get this error message? While trying to install service pack 3 or while trying to install a windows update?
    2. What is the full and exact error message?

    Please answer these questions and tell us more about the issue, it could help us help you better.

    See the bottom of the articles that might help you.
    You cannot install some programs or updates
    http://support.Microsoft.com/kb/822798
    How to troubleshoot an installation fails on Windows XP Service Pack 3
    http://support.Microsoft.com/kb/950718

  • I'm trying to install Quicktime / itunes, but I still find the icon indicating that there is another ongoing installation. I tried to see what the installation is still ongoing, but have'nt found nothing. Help please..!

    I'm trying to install Quicktime / itunes, but I still find the icon indicating that there is another ongoing installation. I tried to see what the installation is still ongoing, but have'nt found nothing. Help please..!

    Hi JDSoor,

    Thanks for posting. Two or more instances of the service Msiexec.exe cannot be launched at the same time for two different products. An install or repair processes should finish before the other process can be launched. Go to processes in the Manager of tasks (so press CTRL ALT + DELETE) then press the processes tab and look for to MSiexec.exe and press "end process." You may need to do more than once.

    I hope this helps. Let us know if this or do not resolve your problem.

    Thank you

    Shawn

    Shawn - Support Engineer - MCP, MCDST
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • I can't send or receive any e-mail and the error code: 0x800CCC19 I call the provider and they say it's a software problem. Help, please

    I can't send or receive any e-mail and the error code: 0x800CCC19 I call the provider and they say it's a software problem.  Help, please

    1. Windows Mail.  But he argued that email account for more than a year without problem.

    2 here is the full error message:

    "Are subject: how pumpkin pies are made ', account: 'pop3.live.com', server: 'smtp.live.com', Protocol: SMTP, Port: 25, secure (SSL): Yes, error number: 0x800CCC19.

    ("How pumpkin pies are doing it" the subject of an email I tried to answer to and it does not work)

    I get another message when sending email: "your POP2 server has not responded in 60 seconds.  You want to wait 60 seconds for the server to respond? »

    And I'm waiting for 60 seconds, several times and it does not send

    It was 1 year there, not more. Not sure when it started.
    Read this article from Microsoft Help Support &:

    http://support.Microsoft.com/default.aspx/KB/926374

    t-4-2

  • I can´t use the USB ports on my monitor dell 1905fp using win7. Help, please.

    I can´t use the USB ports on my monitor dell 1905fp using win7. Help, please.

    Have you plugged your monitor with a USB cable to your computer?

  • Hi, I really need help... I can't find any broadcasting EBU-100/75, test your 1 KhZ, etc... I m going to do 15 masters short for Swedish broadcasting channel at night. -haha! and I can't find anything inside the first... I m I'm blind! Help, please! Vanle

    Hi, I really need help... I can't find any broadcasting EBU-100/75, test your 1 KhZ, etc... I m going to do 15 masters short for Swedish broadcasting channel at night. -haha! and I can't find anything inside the first... I m I'm blind! Help, please! Paris looks Jokum

    Bay3Bob - you are great! Thanxxx :-)

  • I have an account but cannot modify/use the tools.  I went from computers a week ago.  Help, please.

    I have an account but cannot modify/use the tools.  I went from computers a week ago.  Help, please.

    It should not, but you will need to download the right software to use. Adobe Acrobat Reader is what you are currently using. This is why you don't have the tools you are used to.

    Adobe Acrobat (not Reader), that's what you signed up for. He has the tools, you need and are a completely different, even if application you may have initially subscribed by using Adobe Acrobat Reader.

  • First pro cc application failed to start properly (0xc000001d) click on OK to close the application. I get this message after update software. Help, please

    First pro cc application failed to start properly (0xc000001d) click on OK to close the application. I get this message after update software. Help, please!

    Hi RC,.

    Update first Pro CC 2015 (9.2).

    Thank you

    Kevin

  • Read bit in the TCP connection

    Hello

    I'm trying to read data from TCP connection.

    As I understand it, I get a string as this login data.

    I need to play different songs in these data

    What will be the best way to do it?

    Thank you

    In this case, you will get a string of one character in the TCP/IP Read function. You said you want to see if, for example, the character ".<". the="" ascii="" code="" for=""><" is="" hex="" 3c,="" which="" corresponds="" to="" 00111100.="" thus,="" it="" sounds="" like="" you="" just="" need="" to="" make="" a="" comparison="" against="" a="" character.="" if="" you="" want="" to="" check="" a="" specific="" bit="" pattern="" then="" the="" easiest="" way="" to="" do="" this="" is="" to="" simply="" convert="" the="" string="" character="" to="" a="" u8="" and="" compare="" to="" a="" u8="" constant,="" like="">

  • What happened to security.warn the settings about: config. They are absent in FF25. Help, please!

    Hello

    I'm upgrading from Firefox 15 to 25 of Firefox.
    I used to be able to set the following security warnings in: config.

    Security.warn_entering_secure
    Security.warn_entering_weak
    Security.warn_leaving_secure
    Security.warn_submit_insecure
    Security.warn_viewing_mixed

    No more. Looks like these are missing from Firefox 25.
    Help, please! Urgent.

    Thank you.
    SR.

    warnings about the output of a secure site disappeared completely, you would have to look out for the security at the beginning of the address bar indicator to get that information on a site: https://blog.mozilla.org/ux/2012/06/site-identity-ui-updates/

    or use an extension like this for better visibility: https://addons.mozilla.org/firefox/addon/safe/

    the dialog box warning about sending data on a channel not secure to a secure site is still in place.

  • Since the update, I get a message "unable to connect". Explorer Windows has no problem connecting to ADSL. Help, please. I don't like Win Explorer! Thank you

    Help, please. I can't access the internet through my DSL since the upgrade.

    Your firewall is not recognizing the new version of Firefox. Remove Firefox from the list of allowed programs in your firewall, restart Firefox and go to any website, give Firefox the permissions he needs access to the internet.

    See: https://support.mozilla.com/en-US/kb/Cannot%20connect%20after%20upgrading%20Firefox

    If this answer solved your problem, please click 'Solved It' next to this response when connected to the forum.

Maybe you are looking for

  • Restoration of new SSD to timemachine

    I just put in a new SSD in my 2010 macbook pro (IIRC) 10.11.2 running. I have a Time Machine recently saved on an external backup. I tried to use internet to reinstall the OS, which worked. Then I sailed on my external hard drive for the restoration

  • Tecra A9 - Toshiba Assist button doen't answer

    My buttons the "Toshiba Assist:" and the button below that does not also when I use them.Can someone help me how I could go about doing work? * I've tried use / installation application Toshiba Assist. He tells me to reboot the system, but it still d

  • Why can't I delete a message sitting in "sent".

    I have a message sitting in "sent" and I can't delete it – why not?

  • Router Befw11s4 - WARNING long post

    I bought a router of v.4 befw11s4 a couple of years back.  I remember spending hours with tech support to make it work, and even after that I got it working it never worked very well.  The router would reset continually itself, which would require me

  • Cannot open Raw of Mark III Canon 1DX files in CS6. [A: Plugin Raw 9.5.1]

    I just bought the Canon Mark III 1DX, I need the 9.5.1 plug to open RAW in Photoshop CS 6 files, I have downloaded and installed successfully on my Mac I also installed the DNG Converter... and yet, I can't open files in Photoshop? Any help appreciat