I am having trouble with a TCP connection being denied. Here is my setup. My main firewall is a Cisco ASA 5505 (192.168.1.1). I also have another VPN concentrator device for some corporate VPN connectivity (Nortel Contivity) (192.168.1.253). I can successfully AnyConnect VPN into my ASA5505 and use any local resources just fine. My Clients are being assigned on the same subnet as my internal nework via DHCP (192.168.1.x). I have a route for the 199.62.252.0 network to my Nortel Contivity VPN concentrator to let my ASA VPN clients access those VPN's across the nortel. I have added the networks into the nat exclusion list and am able to ping the hosts across my AnyConnect VPN which then gets routed to the Nortel. When I try to access a web page across the VPN i get Deny TCP (no Connection) errors. I can see that the TCP connection is being built, but i am still getting the Deny Messages. i have also attached my ASA configuration.
ASA Deny Messages
Built inbound TCP connection 23778 for outside:192.168.1.51/3473 (192.168.1.51/3473) to inside:199.62.252.243/80 (199.62.252.243/80) (vpnuser)
Deny TCP (no connection) from 199.62.252.243/80 to 192.168.1.51/3473 flags SYN ACK on interface outside
Deny TCP (no connection) from 199.62.252.243/80 to 192.168.1.51/3473 flags SYN ACK on interface outside
Deny TCP (no connection) from 199.62.252.243/80 to 192.168.1.51/3473 flags PSH ACK on interface outside
Deny TCP (no connection) from 199.62.252.243/80 to 192.168.1.51/3473 flags PSH ACK on interface outside
Deny TCP (no connection) from 199.62.252.243/80 to 192.168.1.51/3473 flags PSH ACK on interface outside
Deny TCP (no connection) from 199.62.252.243/80 to 192.168.1.51/3473 flags PSH ACK on interface outside
Deny TCP (no connection) from 199.62.252.243/80 to 192.168.1.51/3473 flags RST ACK on interface outside
Deny TCP (no connection) from 199.62.252.243/80 to 192.168.1.51/3473 flags RST on interface outside
Any help would be appreciated.
Thanks in advance.
Start Free Trial