ASA 5510 can't access one web site, all others fine
Posted on 2014-04-24
By no means an ASA expert, someone else configured it for us. Anyways, here is my problem. I can access every site on the Internet except one.
I can access the site in question using another ISP, but not from my main LAN feed. I called our ISP and they indicated everything was fine with them. As a test I connected a laptop outside our firewall, directly to our Internet router. When I did that I can magically access the site! This means our ISP is correct and the issue isn't on their end, it seems to be something in our ASA config that is causing the problem.
I have tried logging our ASA while trying to access from my desktop and I am seeing the following error:
....duration 0:00:30 bytes 0 SYN Timeout
a few seconds later I see:
....flags RST on interface outside
The timeout message is usually displayed after approximately 30 seconds. The RST error message about 15 seconds after that.
I can't find anything in our configuration specifying something different for this IP address, so I don't know why the ASA is dropping packets to it. As I said, if I move my machine to the network which the outside interface is using, I can connect up no problem.
Any suggestions on this? It's really puzzling this occurs with this one web site only.