Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: Reset-O from everyone!

Re: Reset-O from everyone!

From: Chris Myers <clmmacunix_at_charter.net>
Date: Wed, 7 May 2008 14:40:43 -0500

Bill,

         Check your inspect features and make sure that it is not
dropping your connections due to header issues. Remove http and smtp
and see if there is a difference. If they are not in there, then you
must look at connection counts, MSS, and MTU. You will be able to
determine these via the pcap your running.

Thank You,

Chris Myers
clmmacunix_at_charter.net

John 1:17
For the Law was given through Moses; grace and truth were realized
through Jesus Christ.

    Go Vols!!!!

On May 6, 2008, at 2:52 PM, Bill O'Connell wrote:

>
> Hello,
>
> I have been having a problem with my new cisco ASA 5505. In ftp,
> http and SMTP traffic I keep getting Reset-O. Then (especially with
> the HTTP file transfers we do) I get 1 or sometimes many Deny TCP
> (no connection).
>
> I have a real hard time believing that all of these outside hosts
> are doing Resets - and then still trying to communicate.
>
> Cisco is looking at a pcap now, and it does show retransmissions
> from our web server to the host.
>
> Has anyone seen this kind of behavior before? Does anyone have any
> suggestions? Could it be that there is a faulty router at our ISP?
>
> Everything works flawlessly inside of our network.
>
>
>
> Thanks,
>
> Bill O'Connell
> Network Solutions Manager
> boconnell_at_libertycreativesolutions.com
> 708-633-7450
>
>
> NOTICE: This Liberty Creative Solutions, Inc. e-mail transmission
> (including any file attachment) is intended only for the use of the
> individual or entity to which it is addressed, and may contain
> information that is privileged and confidential, the disclosure of
> which is governed by applicable law. If you are not the intended
> recipient, any dissemination, distribution or copying of this
> communication is strictly prohibited. If you have received this
> communication in error, please notify the sender immediately by
> reply e-mail or a collect telephone call and delete or destroy all
> copies of this message and any file attachment. Thank you!
>
> --
> This message has been scanned for viruses and
> dangerous content by OpenProtect(http://www.openprotect.com), and is
> believed to be clean.
>
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards_at_listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Received on May 07 2008
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos