We use a PIX515 to allow users to connect to our internal network from home using a VPN connection. Each time a user start a VPN connection, lots of error messages appears on the Syslog. Here are some errors from the syslog. Any idea??
192.168.10.x are the IP addresses dynamically given to the VPN clients through a local DHCP pool (W2K) the other IP addresses are on the web.
Apr 09 13:44:52 10.203.24.3 Apr 09 2002 12:41:48: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:80.200.133.49/1214 dst outside:194.51.118.134/62512
Apr 09 13:44:52 10.203.24.3 Apr 09 2002 12:41:48: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:192.168.10.2/2267 dst outside:216.200.241.66/80
Apr 09 13:44:52 10.203.24.3 Apr 09 2002 12:41:48: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:192.168.10.2/2268 dst outside:216.200.241.66/80
Apr 09 13:45:13 10.203.24.3 Apr 09 2002 12:42:09: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:192.168.10.2/2270 dst outside:216.200.241.66/80
Apr 09 13:48:12 10.203.24.3 Apr 09 2002 12:45:09: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2271 dst outside:195.238.2.21/53
Apr 09 13:48:14 10.203.24.3 Apr 09 2002 12:45:11: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2271 dst outside:195.238.2.21/53
Apr 09 13:48:16 10.203.24.3 Apr 09 2002 12:45:13: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2271 dst outside:195.238.2.21/53
Apr 09 13:48:20 10.203.24.3 Apr 09 2002 12:45:17: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2271 dst outside:195.238.2.21/53
Apr 09 13:48:24 10.203.24.3 Apr 09 2002 12:45:20: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2274 dst outside:195.238.2.21/53
Apr 09 13:48:31 10.203.24.3 Apr 09 2002 12:45:28: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2274 dst outside:195.238.2.21/53
Apr 09 13:48:33 10.203.24.3 Apr 09 2002 12:45:30: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2274 dst outside:195.238.2.21/53
Apr 09 13:48:34 10.203.24.3 Apr 09 2002 12:45:30: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:192.168.10.2/2273 dst outside:206.184.151.217/80
192.168.10.x are the IP addresses dynamically given to the VPN clients through a local DHCP pool (W2K) the other IP addresses are on the web.
Apr 09 13:44:52 10.203.24.3 Apr 09 2002 12:41:48: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:80.200.133.49/1214 dst outside:194.51.118.134/62512
Apr 09 13:44:52 10.203.24.3 Apr 09 2002 12:41:48: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:192.168.10.2/2267 dst outside:216.200.241.66/80
Apr 09 13:44:52 10.203.24.3 Apr 09 2002 12:41:48: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:192.168.10.2/2268 dst outside:216.200.241.66/80
Apr 09 13:45:13 10.203.24.3 Apr 09 2002 12:42:09: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:192.168.10.2/2270 dst outside:216.200.241.66/80
Apr 09 13:48:12 10.203.24.3 Apr 09 2002 12:45:09: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2271 dst outside:195.238.2.21/53
Apr 09 13:48:14 10.203.24.3 Apr 09 2002 12:45:11: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2271 dst outside:195.238.2.21/53
Apr 09 13:48:16 10.203.24.3 Apr 09 2002 12:45:13: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2271 dst outside:195.238.2.21/53
Apr 09 13:48:20 10.203.24.3 Apr 09 2002 12:45:17: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2271 dst outside:195.238.2.21/53
Apr 09 13:48:24 10.203.24.3 Apr 09 2002 12:45:20: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2274 dst outside:195.238.2.21/53
Apr 09 13:48:31 10.203.24.3 Apr 09 2002 12:45:28: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2274 dst outside:195.238.2.21/53
Apr 09 13:48:33 10.203.24.3 Apr 09 2002 12:45:30: %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.10.2/2274 dst outside:195.238.2.21/53
Apr 09 13:48:34 10.203.24.3 Apr 09 2002 12:45:30: %PIX-3-106011: Deny inbound (No xlate) tcp src outside:192.168.10.2/2273 dst outside:206.184.151.217/80