Hi everyone,
I am trying ssh to server where ssh traffic passes via Enterprise firewall.
Here are logs
5 2015/04/09
22:10:42.254 MDT 10.16.102.17 Apr 10 00:10:42 WM300 auditd:
date="2015-04-10 04:10:42
+0000",fac=f_ssh_proxy,area=a_libproxycommon,type=t_nettraffic,pri=p_major,pid=4283,logid=0,cmd=sshp,hostname=FWM300.com,event="session
drop",netsessid=2e34455274d33,srcip=172.31.23.107,srcport=56902,srczone=internal,protocol=6,dstip=10.16.102.30,dstport=22,dstzone=external,rule_name="ssh
Proxy Managment",cache_hit=0,start_time="2015-04-10 04:10:27
+0000",application=SSH
Regards
Mike
Solved! Go to Solution.
Do tcpdumps and you'll see it's not a firewall issue.
Some device outside the firewall sent a RST for this connection; that's what 'session drop' means here.
So need to confirm its not issue with Mcafee firewall right?
Regards
Mike
Do tcpdumps and you'll see it's not a firewall issue.
Many thanks
Regards
Mike
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA