- 积分
- 171
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 注册时间
- 2014-11-20
- 最后登录
- 1970-1-1
- 阅读权限
- 20
- 听众
- 收听
助理工程师
 
|
服务器是Linux下的tomcat,地址映射是3年前做的,这三年一直正常,但今天(周一)上班后突然发现在Windows下,所有浏览器都无法访问系统,但在Linux下以正常访问 。
具体现象如下:
1、在防火墙内,所有系统通过浏览器都能正常访问系统。
2、在防火墙外,Linux系统全用Firefox和Chrome都能访问防火墙内的系统
3、在防火墙外,Window系统下,IE,Firefox, Chrome都无法访问防火墙内的系统
4、在Linuxt和Windows下,都能正常SSH进防火墙内的服务器。
cisco5520日志配置如下:
ciskefu(config)# show logging setting
Syslog logging: enabled
Facility: 20
Timestamp logging: enabled
Standby logging: disabled
Debug-trace logging: disabled
Console logging: level informational, 13143 messages logged
Monitor logging: disabled
Buffer logging: level errors, 123 messages logged
Trap logging: level warnings, facility 20, 8036 messages logged
History logging: disabled
Device ID: disabled
Mail logging: disabled
ASDM logging: disabled
使用show logging看不出异常:
Nov 27 2017 12:36:41: %ASA-2-106001: Inbound TCP connection denied from 119.84.99.209/443 to 128.128.0.235/16486 flags FIN ACK on interface outside
Nov 27 2017 12:36:41: %ASA-2-106001: Inbound TCP connection denied from 119.84.99.209/443 to 128.128.0.235/52650 flags FIN ACK on interface outside
Nov 27 2017 12:36:41: %ASA-2-106001: Inbound TCP connection denied from 119.84.99.209/443 to 128.128.0.235/7727 flags FIN ACK on interface outside
Nov 27 2017 12:36:53: %ASA-2-106001: Inbound TCP connection denied from 203.208.48.77/443 to 128.128.0.235/8668 flags FIN ACK on interface outside
Nov 27 2017 12:39:01: %ASA-2-106001: Inbound TCP connection denied from 203.208.48.77/443 to 128.128.0.235/26741 flags FIN ACK on interface outside
|
|