<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA - Orphaned Traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4146932#M1073640</link>
    <description>&lt;P&gt;Thanks for the feedback. A quick question. Wouldn't firewall be independent of the client side closure. It is a transit device with it's own timeouts. Also i am seeing it on many different types of traffic SMB, DNS, LDAP etc. Every second or third flow is like this. This is happening so often that it looks like this is normal behaviour.&lt;/P&gt;</description>
    <pubDate>Sun, 06 Sep 2020 08:52:16 GMT</pubDate>
    <dc:creator>asidd</dc:creator>
    <dc:date>2020-09-06T08:52:16Z</dc:date>
    <item>
      <title>ASA - Orphaned Traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4146910#M1073634</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have separate bidirectional rules in my firewall (ASA 5545-X) for different applications (including VoIP). What is puzzling here is if i capture logs for the traffic coming from OUTSIDE (of firewall) back into the segmented environment i am seeing entries that should have been logged under inside interfaces initiating those connections. Reason why i am saying that: i am seeing a lower end source port session logged under the OUTSIDE interface with a higher end DP. Examples:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SA: 10.100.11.20, SP: TCP(88) , DA=10.47.10.42, DP(50014 to 65408)&lt;/P&gt;&lt;P&gt;SA: 10.100.11.20, SP: UDP(53) , DA=10.47.10.37, DP(58146)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the firewall closing the session so it gets logged under a new session under OUTSIDE. Is there a timer issue here i need to check where it waits for a response and if it doesnt see it under a specific amount of time it will log it against the OUTSIDE rather than associating it to a session built from Inside (10.47.x.x)&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2020 05:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4146910#M1073634</guid>
      <dc:creator>asidd</dc:creator>
      <dc:date>2020-09-06T05:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - Orphaned Traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4146921#M1073637</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Do a full packet capture to see the entire flow. I have seen this with smb&lt;BR /&gt;traffic where the connections are not closed properly at the server side&lt;BR /&gt;while they are already close at client side. This makes responses from&lt;BR /&gt;server appear as new conn on firewall especially if they have SYN flag.&lt;BR /&gt;&lt;BR /&gt;*** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sun, 06 Sep 2020 07:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4146921#M1073637</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-09-06T07:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - Orphaned Traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4146932#M1073640</link>
      <description>&lt;P&gt;Thanks for the feedback. A quick question. Wouldn't firewall be independent of the client side closure. It is a transit device with it's own timeouts. Also i am seeing it on many different types of traffic SMB, DNS, LDAP etc. Every second or third flow is like this. This is happening so often that it looks like this is normal behaviour.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2020 08:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4146932#M1073640</guid>
      <dc:creator>asidd</dc:creator>
      <dc:date>2020-09-06T08:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - Orphaned Traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4147640#M1073684</link>
      <description>&lt;P&gt;Any further comments on these from any experts out there?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 06:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-orphaned-traffic/m-p/4147640#M1073684</guid>
      <dc:creator>asidd</dc:creator>
      <dc:date>2020-09-08T06:25:21Z</dc:date>
    </item>
  </channel>
</rss>

