?
Solved

Cisco ASA - Network Routing Issue

Posted on 2009-04-27
5
Medium Priority
?
308 Views
Last Modified: 2012-05-06
Hi,

I am having some issues on my network here, and I have never quite seen anything like it.

I have come over to do some work in the Branch Office and I have installed an Exchange 2007 Server onto the LAN.

But, it itermitently becomes unavailable, ie outlook disconnects, you cannot ping etc.

But the problem cannot be the hardware as this server is also running vmware and the server running with vmware can be pinged and connected to even when the host server cannot.

When it is not available etc I get the below in the ASDM Log:

Inbound TCP connection denied from 192.168.200.68/1628 to companyx-exch01/3389 flags SYN  on interface inside

Does anyone know why I am seeing this?

192.168.200.68 is my client PC and the server companyx-exch01 has an ip address of 192.168.200.13.

Thanks in advance.

Paul
0
Comment
Question by:essexboy80
  • 3
  • 2
5 Comments
 
LVL 15

Expert Comment

by:Voltz-dk
ID: 24242286
Normally when traffic is blocked it will say it is blocked by an access-list, here it claims the traffic was destined for the inside interface itself.
Could you display some parts of the config?  Like interface, nat & statics?
0
 
LVL 1

Author Comment

by:essexboy80
ID: 24242675
Hi,

I had both of these in my config :

static (inside,outside) tcp interface smtp companyx-exch01 smtp netmask 255.255.255.255
static (outside,inside) tcp companyx-exch01 smtp 111.111.111.111(interface ip) smtp netmask 255.255.255.255

I had a play around with some config and removed the following and I think it has fixed it, would this make sense?

Removed :

static (outside,inside) tcp companyx-exch01 smtp 111.111.111.111(interface ip) smtp netmask 255.255.255.255

Seems better now, does that make sense?

Thanks
0
 
LVL 15

Expert Comment

by:Voltz-dk
ID: 24242714
Yes that makes perfect sense.  It was stuff like that I was looking for when I asked you to post these config bits :)
0
 
LVL 1

Author Comment

by:essexboy80
ID: 24242741
so what was what i removed actually doing to cause issue?
0
 
LVL 15

Accepted Solution

by:
Voltz-dk earned 2000 total points
ID: 24242844
In order to get down to the specific details of what happens, I'd need specific details of what you're doing.

But in general, it goes like this.  Statics dictate how the firewall uses proxy-arp, which is different from how routers would do it.
And that errant static makes the firewall respond to your arp request for the exchange, making you send the packet to the firewall - which it then discards since it doesn't have a rule for it.

If you re-enable the problem, and then wait for it to occur, you can verify my statement with "arp -a" - I'm pretty sure you'll see the IP of Exch01 mapped to the Firewall's MAC address.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question