<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Teardown TCP connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4841688#M1100780</link>
    <description>&lt;P&gt;Hello Rob,&lt;/P&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;I have two question to ask as I'm little bit confuse.&lt;/P&gt;&lt;P&gt;Q1 : What is the meaning of term &lt;STRONG&gt;Active Unit&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;Q2 : Is the activity is questionable or I can consider in normal activity?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2023 07:48:35 GMT</pubDate>
    <dc:creator>priyalchavada</dc:creator>
    <dc:date>2023-05-24T07:48:35Z</dc:date>
    <item>
      <title>Teardown TCP connection</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4841585#M1100776</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I'm working as SOC analyst, I'm analyzing CISCO devices and i get one alert regarding&amp;nbsp;Teardown TCP connection from CISCO FTD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;lt;182&amp;gt;May 24 2023 03:53:45 FTDP : %FTD-6-302014: Teardown TCP connection 259297712 for WAN_A:95.214.27.136/43134 to DMZ:172.16.100.4/5555 duration 0:00:30 bytes 0 Failover primary closed\n&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please explain the exact scenario behind this event occure.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 04:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4841585#M1100776</guid>
      <dc:creator>priyalchavada</dc:creator>
      <dc:date>2023-05-24T04:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Teardown TCP connection</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4841647#M1100778</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1518733"&gt;@priyalchavada&lt;/a&gt; the FTD SYSLOG messages are all documented. Your syslog message 302014 ID states the reason was - "The standby unit in a failover pair deleted a connection because of a message received from the active unit."&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/Syslogs/b_fptd_syslog_guide/syslogs3.html#con_6941209" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/Syslogs/b_fptd_syslog_guide/syslogs3.html#con_6941209&lt;/A&gt;&lt;/P&gt;
&lt;H3 id="con_6941209__title_dfp_fcq_wbb" class="title topictitle3"&gt;302014&lt;/H3&gt;
&lt;SECTION class="body conbody"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Error Message&lt;/STRONG&gt;&lt;CODE class="ph codeph"&gt; %&lt;SPAN class="ph"&gt;FTD&lt;/SPAN&gt;-6-302014:
 Teardown [Probe] TCP 
connection&amp;nbsp;id&amp;nbsp;for&amp;nbsp;interface&amp;nbsp;:real-address&amp;nbsp;/real-port&amp;nbsp;[(idfw_user&amp;nbsp;)] 
to&amp;nbsp;interface&amp;nbsp;:real-address&amp;nbsp;/real-port&amp;nbsp;[(idfw_user&amp;nbsp;)]
                                 duration&amp;nbsp;hh:mm:ss&amp;nbsp;bytes&amp;nbsp;bytes&amp;nbsp;[reason 
[from teardown-initiator]] [(user&amp;nbsp;)]&lt;/CODE&gt;&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Explanation&lt;/STRONG&gt; A TCP connection between two hosts was deleted. The following list describes the message values:&lt;/P&gt;
&lt;UL id="con_6941209__ul_B827A3848FD64FE880562A8929E855E5" class="ul"&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;probe&lt;/SPAN&gt;—Indicates the TCP connection is a probe connection&lt;SPAN class="ph uicontrol"&gt;id&lt;/SPAN&gt; —A unique identifier&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="con_6941209__li_07548D6978D445DFBB57245E12CD955E" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;interface, real-address, real-port&lt;/SPAN&gt;—The actual socket&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="con_6941209__li_F0F00A2E758F47B1915C4094A425C7F7" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;duration&lt;/SPAN&gt;—The lifetime of the connection&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="con_6941209__li_476DD9A9014944428DD67311819D3C97" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;bytes&lt;/SPAN&gt;&lt;EM class="ph i"&gt;—&lt;/EM&gt; The data transfer of the connection&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="con_6941209__li_4CBFDC7330504FDEAB3AA116AB6C302E" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;User&lt;/SPAN&gt;—The AAA name of the user&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;idfw_user&lt;/STRONG&gt; —The name of the identity firewall user&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;reason&lt;/SPAN&gt;—The action that causes the connection to terminate. Set the &lt;SPAN class="ph uicontrol"&gt;reason&lt;/SPAN&gt; variable to one of the TCP termination reasons listed in the following table.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;teardown-initiator&lt;/STRONG&gt;—Interface name of the side that initiated the teardown.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="tableContainer"&gt;
&lt;TABLE class="table" border="1" width="100%"&gt;&lt;CAPTION&gt;&lt;SPAN class="table--title-label tabletitle"&gt;Table 1. &lt;/SPAN&gt;&lt;SPAN class="tabletitle"&gt;TCP Termination Reasons&lt;/SPAN&gt;&lt;/CAPTION&gt;&lt;COLGROUP&gt; &lt;COL /&gt; &lt;COL /&gt; &lt;/COLGROUP&gt;
&lt;THEAD class="thead"&gt;
&lt;TR&gt;
&lt;TH id="con_6941209__entry__1" class="entry"&gt;
&lt;P class="p"&gt;Reason&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="con_6941209__entry__2" class="entry"&gt;
&lt;P class="p"&gt;Description&lt;/P&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Conn-timeout&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;The connection ended when a flow is closed because of the expiration of its inactivity timer.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Deny Terminate&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Flow was terminated by application inspection.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Failover primary closed&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;&lt;STRONG&gt;The standby unit in a failover pair deleted a connection because of a message received from the active unit&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Wed, 24 May 2023 06:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4841647#M1100778</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-05-24T06:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Teardown TCP connection</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4841688#M1100780</link>
      <description>&lt;P&gt;Hello Rob,&lt;/P&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;I have two question to ask as I'm little bit confuse.&lt;/P&gt;&lt;P&gt;Q1 : What is the meaning of term &lt;STRONG&gt;Active Unit&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;Q2 : Is the activity is questionable or I can consider in normal activity?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 07:48:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4841688#M1100780</guid>
      <dc:creator>priyalchavada</dc:creator>
      <dc:date>2023-05-24T07:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Teardown TCP connection</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4846022#M1101052</link>
      <description>&lt;P&gt;FW HA is two FW interconnect to each other is one failed the other will take place to forward inspect data traffic&amp;nbsp;&lt;BR /&gt;to see the right reason check the Log in active FW&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 01:19:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection/m-p/4846022#M1101052</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-31T01:19:24Z</dc:date>
    </item>
  </channel>
</rss>

