Link to home
Start Free TrialLog in
Avatar of Nomad469
Nomad469

asked on

pix 515 and syn flag problems

I have a pix 515 ( 6.3.3) in place and working well.  The outside interface is talking to a 2621 over a vlan...

isp ---------> 2621 outside int
                             |     < --- same vlan
                             |
                    pix outside int  -----> inside networks


I am changing routers and t1 providers... so I change all of my translates, accesslists, globals and routes to reflect the new public network.

the Pix and the new router can see each other AND anything that I put on the "public network VLAN"  but any traffic that the pix is supposed to pass to the inside network(s) come back with the error "inbound tcp connection denyed xxx.xxx.xxx.xxx/port to xxx.xxx.xxx.xxx/80 (or whatever port) SYN flag on interface outside" (in the syslog BTW)

after I change the acls and xlates i do a clear xlate, clear arp and dump the active connections...

I'm baffled and I am sure that it is something simple that I am missing


SOLUTION
Avatar of hawgpig
hawgpig

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Nomad469
Nomad469

ASKER

Ok... I feel rather lame on this one ... I hope that cisco isn't watching they'll want my cert back !!
It was connection based ... when I did the command set in word pad to do all of the changes at the same time ... I did a no on the outside acl without turning it back on ... oopps ! It was something simple... a silly little missing permission. D'oh.

Its working correctly now ... thanks for all your help!