pix 515 and syn flag problems
Posted on 2004-04-11
I have a pix 515 ( 6.3.3) in place and working well. The outside interface is talking to a 2621 over a vlan...
isp ---------> 2621 outside int
| < --- same vlan
pix outside int -----> inside networks
I am changing routers and t1 providers... so I change all of my translates, accesslists, globals and routes to reflect the new public network.
the Pix and the new router can see each other AND anything that I put on the "public network VLAN" but any traffic that the pix is supposed to pass to the inside network(s) come back with the error "inbound tcp connection denyed xxx.xxx.xxx.xxx/port to xxx.xxx.xxx.xxx/80 (or whatever port) SYN flag on interface outside" (in the syslog BTW)
after I change the acls and xlates i do a clear xlate, clear arp and dump the active connections...
I'm baffled and I am sure that it is something simple that I am missing