<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA PACKET CAPTURE (SWE FLAG) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/4192508#M1076373</link>
    <description>&lt;P&gt;Hi there,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found similar SWE&amp;nbsp; Flag when I did packet capture during tshooting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turns out, there is another device after this firewall which is blocking the traffic.&lt;/P&gt;&lt;P&gt;So , it seem from the packet capture example above -- only Syn is sent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Syn/Ack is not coming back from the destination host. Thus resulting to a TCP timeout.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Raj Veeriah&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2020 03:16:22 GMT</pubDate>
    <dc:creator>Rajavethan Veeriah</dc:creator>
    <dc:date>2020-12-03T03:16:22Z</dc:date>
    <item>
      <title>ASA PACKET CAPTURE (SWE FLAG)</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3307304#M1064703</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need some help from from you guys.&lt;/P&gt;
&lt;P&gt;Today I was doing packet capture on Cisco ASA and during the capture in my logs I saw SWE flag. Can anyone please let me know does it mean&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried googling it but didn’t get accurate answers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate any quick response.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3307304#M1064703</guid>
      <dc:creator>sambillings459</dc:creator>
      <dc:date>2020-02-21T15:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA PACKET CAPTURE (SWE FLAG)</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3307322#M1064704</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please attach a portion of logs/captures where you encountered the SWE flag. You can remove sensitive info as required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jan 2018 07:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3307322#M1064704</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-01-07T07:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA PACKET CAPTURE (SWE FLAG)</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3307596#M1064705</link>
      <description>&lt;P&gt;Okay, found something and makes sense:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://forums.gentoo.org/viewtopic-t-509973-start-0.html" target="_blank"&gt;https://forums.gentoo.org/viewtopic-t-509973-start-0.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 08:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3307596#M1064705</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-01-08T08:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA PACKET CAPTURE (SWE FLAG)</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3307775#M1064706</link>
      <description>24: 09:21:11.405984       1.1.1.1.54116 &amp;gt; 2.2.2.2.9100: SWE 4252812793:4252812793(0) win 8192 &amp;lt;mss 1420,nop,wscale 8,nop,nop,sackOK,opt-33:210081c4862157070000&amp;gt; &lt;BR /&gt;25: 09:21:14.409280       1.1.1.1.54116 &amp;gt; 2.2.2.2.9100: SWE 4252812793:4252812793(0) win 8192 &amp;lt;mss 1420,nop,wscale 8,nop,nop,sackOK,opt-33:210081c4862157070000&amp;gt; &lt;BR /&gt;26: 09:21:17.426094       1.1.1.1.54117 &amp;gt; 2.2.2.2.9100: SWE 2154972116:2154972116(0) win 8192 &amp;lt;mss 1420,nop,wscale 8,nop,nop,sackOK,opt-33:210081c4862157070000&amp;gt; &lt;BR /&gt;27: 09:21:20.428429       1.1.1.1.54117 &amp;gt; 2.2.2.2.9100: SWE 2154972116:2154972116(0) win 8192 &amp;lt;mss 1420,nop,wscale 8,nop,nop,sackOK,opt-33:210081c4862157070000&amp;gt;</description>
      <pubDate>Mon, 08 Jan 2018 14:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3307775#M1064706</guid>
      <dc:creator>sambillings459</dc:creator>
      <dc:date>2018-01-08T14:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA PACKET CAPTURE (SWE FLAG)</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3308266#M1064707</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please refer to my first response. I found a link that explains the tcp options utilising the SWE flags.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 12:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/3308266#M1064707</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-01-09T12:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA PACKET CAPTURE (SWE FLAG)</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/4192508#M1076373</link>
      <description>&lt;P&gt;Hi there,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found similar SWE&amp;nbsp; Flag when I did packet capture during tshooting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turns out, there is another device after this firewall which is blocking the traffic.&lt;/P&gt;&lt;P&gt;So , it seem from the packet capture example above -- only Syn is sent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Syn/Ack is not coming back from the destination host. Thus resulting to a TCP timeout.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Raj Veeriah&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 03:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/4192508#M1076373</guid>
      <dc:creator>Rajavethan Veeriah</dc:creator>
      <dc:date>2020-12-03T03:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA PACKET CAPTURE (SWE FLAG)</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/4691438#M1093550</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/281487"&gt;@sambillings459&lt;/a&gt; SWE es por que tiene SYN+ECN Echo+ECN Cwnd Reducido, por lo que SYN inicial asi utiliza un "paquete SYN de configuración de ECN". Indica que el host que envía el paquete es compatible con ECN.&lt;BR /&gt;"E" tiene SYN+ECN Echo establecido; probablemente también tenga configurado ACK (según el campo "ack" en el paquete), por lo que es una respuesta SYN+ACK al SYN inicial, y es, para usar la terminología en la sección 6.1.1 de RFC 3168, un " Paquete SYN-ACK de configuración ECN". Indica que el host que envía el paquete es compatible con ECN.&lt;BR /&gt;El ECN tiene la bondad de una notificación de congestión de extremo a extremo entre dos puntos de conexión en redes basadas en TCP/IP.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 14:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture-swe-flag/m-p/4691438#M1093550</guid>
      <dc:creator>Jesse Mijares</dc:creator>
      <dc:date>2022-09-21T14:36:39Z</dc:date>
    </item>
  </channel>
</rss>

