<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Teardown TCP Connection on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-on-asa/m-p/5091338#M1112148</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;This syslog event indicates that the state of an UDP "session" was deleted from the connection state of the ASA.&lt;/P&gt;&lt;P&gt;Here the documentation : &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs3.html#con_4770749" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs3.html#con_4770749&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can use the command "sh conn" to check the connection states.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2024 17:06:15 GMT</pubDate>
    <dc:creator>Jerome BERTHIER</dc:creator>
    <dc:date>2024-05-06T17:06:15Z</dc:date>
    <item>
      <title>Teardown TCP Connection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-on-asa/m-p/5088752#M1112084</link>
      <description>&lt;P&gt;Hi Network Greats,&lt;/P&gt;&lt;P&gt;I observed below syslog events on one of ASA device .&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;190&amp;gt;May 03 2024 12:19:10 ICRA-ASA-PRI : %ASA-6-302016: Teardown UDP connection 9832480 for OUTSIDE:65.49.1.115/55845 to identity:10.10.100.4/500 duration 0:02:24 bytes 608&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does this signify that the connection was built out on ASA or connection was terminated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What the exact difference between deny and tear down?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 12:49:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-on-asa/m-p/5088752#M1112084</guid>
      <dc:creator>tanmoymm91</dc:creator>
      <dc:date>2024-05-03T12:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Teardown TCP Connection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-on-asa/m-p/5088789#M1112085</link>
      <description>&lt;P&gt;These are different&lt;/P&gt;
&lt;P&gt;Deny permit is for ACL&lt;/P&gt;
&lt;P&gt;Teardown or build connection is for CONN table'&lt;/P&gt;
&lt;P&gt;Now what you see is traffic from outside to identity (i.e. ASA itself) and traffic is UDP and port is 500 i.e. it is IPSec VPN port' and traffic is teardown i.e. the VPN is down for reason&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 13:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-on-asa/m-p/5088789#M1112085</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-03T13:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Teardown TCP Connection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/teardown-tcp-connection-on-asa/m-p/5091338#M1112148</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;This syslog event indicates that the state of an UDP "session" was deleted from the connection state of the ASA.&lt;/P&gt;&lt;P&gt;Here the documentation : &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs3.html#con_4770749" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs3.html#con_4770749&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can use the command "sh conn" to check the connection states.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:06:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/teardown-tcp-connection-on-asa/m-p/5091338#M1112148</guid>
      <dc:creator>Jerome BERTHIER</dc:creator>
      <dc:date>2024-05-06T17:06:15Z</dc:date>
    </item>
  </channel>
</rss>

