Solved

TCP Reset-I Cisco Firewall

Posted on 2003-12-05
8
9,591 Views
Last Modified: 2013-11-16
Remote user connecting with Terminal Server to map a drive on the server has been able to do this for many months.  Now we are receiving a syslog message as follows:
Teardown TCP connection 3508033 faddr 124.24.126.36/3767 gaddr 165.123.12.161/445 laddr 192.168.1.3/445 duration 0:00:00 bytes 0 (TCP Reset-I)

This occurs even though a Terminal server session runs from the same machine at the same time that port 445 is rejected by the server (if I understand the message correctly).  

User obviously receives a message about network address not found.  This is a server running Win2K Server and the user running Win XP.  

Thanks for your help.
 
0
Comment
Question by:DEllis3
8 Comments
 
LVL 13

Expert Comment

by:td_miles
Comment Utility
What version IOS are you running (use "show version") ?

Have there been any changes to cause this ? Have you upgraded the IOS ? Have you upgraded Terminal Server ? Have you changed OS on the PC ?

If it was working happily, then something must have changed to cause it not to work.
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Has user installed cable router that is now doing DHCP and NAT at home?
Is their local LAN now 192.168.1.x
Is the Term server IP 192.168.1.3 ?
0
 

Author Comment

by:DEllis3
Comment Utility
nicpix up 187 days 19 hours

Hardware:   SE440BX2, 128 MB RAM, CPU Pentium II 350 MHz
Flash i28F640J5 @ 0x300, 16MB
BIOS Flash AT29C257 @ 0xfffd8000, 32KB

0: ethernet0: address is 00d0.b76b.7ee4, irq 11
1: ethernet1: address is 00d0.b73f.e6c9, irq 15
2: ethernet2: address is 00d0.b7a0.9987, irq 10

No change to the firewall.
No change to the OS other than MS patches.
No change to the PC OS (XP) other than MS patches.
Term server IP address on the DMZ is 192.168.1.3.   External address is as shown in the quesion.  

I will have to check with the user when she arrives this morning as to her local IP address and NAT.  She is using cable modemwith a fixed external ip address.  I will post the answer to this last question, but it may be tomorrow as she lives too far to return home and back today.  

Thanks for your help.

0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 

Author Comment

by:DEllis3
Comment Utility
User at home is using cable modem and wireless at home.  Her IP address at home 192.168.1.102, with default gateway 192.168.1.1
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
Comment Utility
There's the problem.
Her local LAN is 192.168.1.x
Your Corp LAN is 192.168.1.x
Her PC thinks that your TS 192.168.1.3 is local and refuses to send through the VPN

Solution=change her local LAN to something else, like 192.168.2.0
I would imagine it being easier to change hers than change your internal corporate LAN?

This is one reason why I always council my clients to never, ever use 192.168.1.0, 192.168.0.0, 10.0.0.0 as their corporate LAN
0
 

Author Comment

by:DEllis3
Comment Utility
We will try that, but I don't think it is the answer:  The external address is the one that she sends to.  We are not using a VPN but rather Terminal Server.  The external address is 165.123.12.161.  She doesn't see the 192.168.1.x address.  Also, she is able to connect to the same IP address using Terminal Server port 3389.  It is only the port 445 for mapping a drive that will not hold the connection.

Thanks for your help.  I will try to have her change her local gateway and see what happens.



0
 
LVL 23

Expert Comment

by:Tim Holman
Comment Utility
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:

--> Accept: lrmoore

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

tim_holman
EE Cleanup Volunteer
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now