Nomad469
asked on
pix 515 and syn flag problems
I have a pix 515 ( 6.3.3) in place and working well. The outside interface is talking to a 2621 over a vlan...
isp ---------> 2621 outside int
| < --- same vlan
|
pix outside int -----> inside networks
I am changing routers and t1 providers... so I change all of my translates, accesslists, globals and routes to reflect the new public network.
the Pix and the new router can see each other AND anything that I put on the "public network VLAN" but any traffic that the pix is supposed to pass to the inside network(s) come back with the error "inbound tcp connection denyed xxx.xxx.xxx.xxx/port to xxx.xxx.xxx.xxx/80 (or whatever port) SYN flag on interface outside" (in the syslog BTW)
after I change the acls and xlates i do a clear xlate, clear arp and dump the active connections...
I'm baffled and I am sure that it is something simple that I am missing
isp ---------> 2621 outside int
| < --- same vlan
|
pix outside int -----> inside networks
I am changing routers and t1 providers... so I change all of my translates, accesslists, globals and routes to reflect the new public network.
the Pix and the new router can see each other AND anything that I put on the "public network VLAN" but any traffic that the pix is supposed to pass to the inside network(s) come back with the error "inbound tcp connection denyed xxx.xxx.xxx.xxx/port to xxx.xxx.xxx.xxx/80 (or whatever port) SYN flag on interface outside" (in the syslog BTW)
after I change the acls and xlates i do a clear xlate, clear arp and dump the active connections...
I'm baffled and I am sure that it is something simple that I am missing
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
It was connection based ... when I did the command set in word pad to do all of the changes at the same time ... I did a no on the outside acl without turning it back on ... oopps ! It was something simple... a silly little missing permission. D'oh.
Its working correctly now ... thanks for all your help!