> packet-tracer input inside-low tcp 10.6.1.150 53176 10.1.1.151 445 Phase: 1 Type: CAPTURE Subtype: Result: ALLOW Elapsed time: 21325 ns Config: Additional Information: MAC Access list Phase: 2 Type: ACCESS-LIST Subtype: Result: ALLOW Elapsed time: 21325 ns Config: Implicit Rule Additional Information: MAC Access list Phase: 3 Type: INPUT-ROUTE-LOOKUP Subtype: Resolve Egress Interface Result: ALLOW Elapsed time: 22178 ns Config: Additional Information: Found next-hop 10.6.254.1 using egress ifc outside(vrfid:0) Phase: 4 Type: ECMP load balancing Subtype: Result: ALLOW Elapsed time: 4265 ns Config: Additional Information: ECMP load balancing Found next-hop 10.6.254.18 using egress ifc inside-low(vrfid:0) Phase: 5 Type: OBJECT_GROUP_SEARCH Subtype: Result: ALLOW Elapsed time: 0 ns Config: Additional Information: Source Object Group Match Count: 5 Destination Object Group Match Count: 3 Object Group Search: 15 Phase: 6 Type: OBJECT_GROUP_SEARCH Subtype: Result: ALLOW Elapsed time: 853 ns Config: Additional Information: Phase: 7 Type: ACCESS-LIST Subtype: log Result: ALLOW Elapsed time: 853 ns Config: access-group CSM_FW_ACL_ global access-list CSM_FW_ACL_ advanced permit tcp ifc inside-low object <10.6.1.150> ifc outside object <10.1.1.151> object-group SMB-TCP rule-id 268449798 access-list CSM_FW_ACL_ remark rule-id 268449798: ACCESS POLICY: basic-access - Mandatory access-list CSM_FW_ACL_ remark rule-id 268449798: L7 RULE: Test-Share-Rule object-group service SMB-TCP tcp port-object eq 445 Additional Information: This packet will be sent to snort for additional processing where a verdict will be reached Phase: 8 Type: CONN-SETTINGS Subtype: Result: ALLOW Elapsed time: 853 ns Config: class-map class-default match any policy-map global_policy class class-default set connection advanced-options UM_STATIC_TCP_MAP service-policy global_policy global Additional Information: Phase: 9 Type: NAT Subtype: per-session Result: ALLOW Elapsed time: 853 ns Config: Additional Information: Phase: 10 Type: IP-OPTIONS Subtype: Result: ALLOW Elapsed time: 853 ns Config: Additional Information: Phase: 11 Type: FOVER Subtype: standby-update Result: ALLOW Elapsed time: 43503 ns Config: Additional Information: Phase: 12 Type: OBJECT_GROUP_SEARCH Subtype: Result: ALLOW Elapsed time: 88712 ns Config: Additional Information: Phase: 13 Type: NAT Subtype: per-session Result: ALLOW Elapsed time: 1706 ns Config: Additional Information: Phase: 14 Type: IP-OPTIONS Subtype: Result: ALLOW Elapsed time: 853 ns Config: Additional Information: Phase: 15 Type: FLOW-CREATION Subtype: Result: ALLOW Elapsed time: 72505 ns Config: Additional Information: New flow created with id 362076620, packet dispatched to next module Phase: 16 Type: EXTERNAL-INSPECT Subtype: Result: ALLOW Elapsed time: 34973 ns Config: Additional Information: Application: 'SNORT Inspect' Phase: 17 Type: SNORT Subtype: firewall Result: DROP Elapsed time: 125876 ns Config: Network 0, Inspection 0, Detection 2, Rule ID 268434432 Additional Information: Starting rule matching, zone -1 -> -1, geo 0 -> 0, vlan 0, src sgt: 0, src sgt type: unknown, dst sgt: 0, dst sgt type: unknown, user 9999997, no url or host, no xff Matched rule ids 268434432 - Block Result: input-interface: inside-low(vrfid:0) input-status: up input-line-status: up output-interface: outside(vrfid:0) output-status: up output-line-status: up Action: drop Time Taken: 441486 ns Drop-reason: (firewall) Blocked or blacklisted by the firewall preprocessor, Drop-location: frame 0x000000aaae91ea1c flow (NA)/NA >