106023: Deny tcp src outside from WWW Servers

From: Rene Obrecht (groups_at_no-woman-no-cry.ch)
Date: 09/07/05


Date: 7 Sep 2005 05:04:10 -0700

Dear all, we have a Cisco PIX 525, SW Release 6.3.4.

We have an ISA Proxy Server in our DMZ, the WWW Clients connect to this
ISA Proxy Server. This goes directly to the Internet.

There are many many entries like this in the Firewall log. Everything
works fine, but what about the warnings?

%PIX-4-106023: Deny tcp src outside:ISAPROXY/8080 dst
inside:172.25.111.158/2377 by access-group "dmz_to_intranet"

I guess the warnings are because there are answers from WWW Servers,
and no client waiting for them. Any Ideas?

Thanks, René



Relevant Pages

  • ODBC Drivers error 80004005 OR "HTTP 500 - Internal server error
    ... There are two ISA proxy server configured with Integrated NLB. ... http://www.idccircle.com/register.asp from his XP SP2 PC. ... the same URL without any problem from my notebook which connected to Internet ... via broadband connection ...
    (microsoft.public.isa)
  • Re: ISA Proxy Server - Timeout Issue
    ... Doesn't seem to be a "settings" problem. ... Most likely the firewall services ... I am working in an organization, where Internet is accessed ... This is because request from the ISA Proxy Server gets ...
    (microsoft.public.isa)
  • Re: configuring MS ISA server to be a public web proxy server
    ... Add the IP from the external interface to LAT. ... > which I want to surf the internet through the ISA proxy server. ...
    (comp.security.firewalls)
  • Re: configuring MS ISA server to be a public web proxy server
    ... > You can set your internal and external ipadresses. ... Do you mean that I should add all possible addresses to the LAT? ... So let's say there is one particular computer on the internet from ... which I want to surf the internet through the ISA proxy server. ...
    (comp.security.firewalls)

Quantcast