TCP Reset-I Cisco Firewall

Remote user connecting with Terminal Server to map a drive on the server has been able to do this for many months.  Now we are receiving a syslog message as follows:
Teardown TCP connection 3508033 faddr 124.24.126.36/3767 gaddr 165.123.12.161/445 laddr 192.168.1.3/445 duration 0:00:00 bytes 0 (TCP Reset-I)

This occurs even though a Terminal server session runs from the same machine at the same time that port 445 is rejected by the server (if I understand the message correctly).  

User obviously receives a message about network address not found.  This is a server running Win2K Server and the user running Win XP.  

Thanks for your help.
 
DEllis3Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

td_milesCommented:
What version IOS are you running (use "show version") ?

Have there been any changes to cause this ? Have you upgraded the IOS ? Have you upgraded Terminal Server ? Have you changed OS on the PC ?

If it was working happily, then something must have changed to cause it not to work.
0
lrmooreCommented:
Has user installed cable router that is now doing DHCP and NAT at home?
Is their local LAN now 192.168.1.x
Is the Term server IP 192.168.1.3 ?
0
DEllis3Author Commented:
nicpix up 187 days 19 hours

Hardware:   SE440BX2, 128 MB RAM, CPU Pentium II 350 MHz
Flash i28F640J5 @ 0x300, 16MB
BIOS Flash AT29C257 @ 0xfffd8000, 32KB

0: ethernet0: address is 00d0.b76b.7ee4, irq 11
1: ethernet1: address is 00d0.b73f.e6c9, irq 15
2: ethernet2: address is 00d0.b7a0.9987, irq 10

No change to the firewall.
No change to the OS other than MS patches.
No change to the PC OS (XP) other than MS patches.
Term server IP address on the DMZ is 192.168.1.3.   External address is as shown in the quesion.  

I will have to check with the user when she arrives this morning as to her local IP address and NAT.  She is using cable modemwith a fixed external ip address.  I will post the answer to this last question, but it may be tomorrow as she lives too far to return home and back today.  

Thanks for your help.

0
Increase Security & Decrease Risk with NSPM Tools

Analyst firm, Enterprise Management Associates (EMA) reveals significant benefits to enterprises when using Network Security Policy Management (NSPM) solutions, while organizations without, experienced issues including non standard security policies and failed cloud migrations

DEllis3Author Commented:
User at home is using cable modem and wireless at home.  Her IP address at home 192.168.1.102, with default gateway 192.168.1.1
0
lrmooreCommented:
There's the problem.
Her local LAN is 192.168.1.x
Your Corp LAN is 192.168.1.x
Her PC thinks that your TS 192.168.1.3 is local and refuses to send through the VPN

Solution=change her local LAN to something else, like 192.168.2.0
I would imagine it being easier to change hers than change your internal corporate LAN?

This is one reason why I always council my clients to never, ever use 192.168.1.0, 192.168.0.0, 10.0.0.0 as their corporate LAN
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
DEllis3Author Commented:
We will try that, but I don't think it is the answer:  The external address is the one that she sends to.  We are not using a VPN but rather Terminal Server.  The external address is 165.123.12.161.  She doesn't see the 192.168.1.x address.  Also, she is able to connect to the same IP address using Terminal Server port 3389.  It is only the port 445 for mapping a drive that will not hold the connection.

Thanks for your help.  I will try to have her change her local gateway and see what happens.



0
Tim HolmanCommented:
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:

--> Accept: lrmoore

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

tim_holman
EE Cleanup Volunteer
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.