Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

I have an ASA with the following:  What does the following mean?   "Deny TCP (no connection) from/to flags FIN ACK on interface inside"

Posted on 2009-07-15
4
Medium Priority
?
1,271 Views
Last Modified: 2013-11-22
I keep getting the above error.  It is not explicitly denying the packet, but was wondering what the error means.
0
Comment
Question by:NWSBexch
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 24863766
It means basically the TCP packet was sent with something other than the syn flag sent. Therefore the ASAwould check its connection table, no previous connection existed and the packet gets denied.
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 24863807
But I seen this messege when I used 8.0.4 on 5505 with Oracle communication, after that I downgraded the ASA the problem is discontinued!

Do you have a problem on qour network, or you inquiring?
0
 
LVL 15

Accepted Solution

by:
Voltz-dk earned 1500 total points
ID: 24865169
It is a common log.  It's a packet that is received after the connection has been closed down in the ASA.
If you have syslog on informational, you'll see that you receive a Teardown syslog (which also states why it's closed) on the connection in question prior to this deny.
The packet is indeed denied, but it's got FIN flag set so it's part of the graceful connection teardown anyways.
0
 

Author Comment

by:NWSBexch
ID: 24865182
So this is not necessarily a bad thing, but just part of the "tear down" process?
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question