Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

New to PIX 515E - Question re Service Resetoutside Command

Status
Not open for further replies.

rcbear

Technical User
Sep 16, 2002
3
US
Hello,

One of the ISP's I connect to for POP3 mail sends an ACK request from a different IP address than the POP3 server's each time I log on to check email. This causes timeout problems. The PIX log entries read, "Deny TCP (no connection) from xxx.xx.xxx.xxx/80 to xxx.xxx.xxx.xxx/1982 flags ACK on interface outside".

The "service resetoutside" command eliminates the problem, but it also makes my system non-stealthy when port scanned. Is there a way I can establish a rule that will cause the PIX to respond to ACK requests from only certain IP's?

Thanks very much,

RCBEAR
 
Have you tried connecting to that different IP directly instead? Maybe their email server has multiple ips bound to it, and it's replying from it's primary ip only.

Never the less, your PIX is doing the right thing by denying packets trying to impersinate connections.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top