troubleshooting Question

Site-to-Site VPN Deny TCP SYN ACK on interface outside

Avatar of frukeus
frukeusFlag for Singapore asked on
RoutersVPNCisco
7 Comments5 Solutions2712 ViewsLast Modified:
I have created a Site-to-Site VPN for 2 ASA firewalls and is able to ping both internal subnets with no problem.
However, on 1 print server 192.168.2.4 which is hosting a remote printer 172.10.100.100, I can unable to print. From the print server, i ran ping test and I can successfully ping 172.10.100.100.
On the firewall log at 192.168.1.253, I get the following message which I believe is the problem-

Teardown TCP connection 12979303 for outside: 172.10.100.100/9100 to inside 192.168.2.4/2172 duration 0:00:00 bytes 0 TCP Reset-I
Deny TCP (no connection) from 172.10.100.100/9100 to 192.168.2.4/2172 flags SYN ACK on interface outside

192.168.2.4 (Print Server)
|
192.168.2.1  (Router)
|
192.168.1.253 (ASA)
||
VPN Tunnel
||
172.10.100.253 (ASA)
|
172.10.100.100   (printer)
ASKER CERTIFIED SOLUTION
Grape_Soda

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 5 Answers and 7 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 5 Answers and 7 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros