![]() |
Available news archives:
comp.lang.tcl
-
comp.lang.python
-
comp.security.firewalls
-
sci.crypt -
comp.lang.php -
comp.lang.javascript
|
|
comp.security.firewalls archiveRe: Deny TCP (no connection) flags RST on inside intf ? PIX 6.3.5
From: Walter Roberson <roberson@hushmail.com>
Date: Fri Apr 14 2006 - 19:08:19 CEST
In article <1145033606.604157.220140@t31g2000cwb.googlegroups.com>,
PIX questions are better addressed to comp.dcom.sys.cisco -- there
>and in the syslogs I'm seeing enough of the following messages that I'm
>08:01:53 Local4.Info 10.0.0.5 Apr 14 2006 12:01:36: %PIX-6-302013:
Normal message.
>08:01:53 Local4.Info 10.0.0.5 Apr 14 2006 12:01:36: %PIX-6-302014:
Normal message.
>
>08:01:53 Local4.Info 10.0.0.5 Apr 14 2006 12:01:36: %PIX-6-106015:
>I would expect these more on the outside intf where the pix shuts down
The same thing can happen: the outside host can shut down the connection
The problem started in PIX 6.2(2) or so: the PIX no longer holds on
Notice that the first of the messages was RST ACK: that implies that
You might be able to play with the "timeout" parameters, but I don't
|