<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Investigate new TCP connections from specific port (HTTPS) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/investigate-new-tcp-connections-from-specific-port-https/m-p/3830722#M11541</link>
    <description>&lt;P&gt;hmm... here some of the tips you can you to see what is happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show conn 192.168.20.71&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;show local-host 192.168.20.71 or show local-host 192.168.20.71 brief&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;show service-policy flow tcp host 192.168.20.71 host 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2019 14:59:10 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2019-04-02T14:59:10Z</dc:date>
    <item>
      <title>Investigate new TCP connections from specific port (HTTPS)</title>
      <link>https://community.cisco.com/t5/network-security/investigate-new-tcp-connections-from-specific-port-https/m-p/3830398#M11540</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I think i have a very simple question. We have a server making a lot of HTTPS connections to different IP's. We have a a specific rule in our ACL for this traffic. When building the firewall rules, i still noticed a lot of hits on the permit ip any-any rule so i digged deeper.&lt;/P&gt;&lt;P&gt;I found that this same server was building outbound TCP connections, but with the&amp;nbsp;&lt;STRONG&gt;source port&lt;/STRONG&gt; of tcp/443. Like this:&lt;/P&gt;&lt;PRE&gt;2019-04-02 08:40:36	Local6.Notice	192.168.20.71	Apr 02 2019 08:41:07: %ASA-5-106100: access-list LSPXSG4_access_in permitted tcp LSPXSG4/LSPAPPAMD211(443) -&amp;gt; Zorgnet/172.24.140.201(14728) hit-cnt 1 first hit [0x221dee80, 0x00000000]&lt;/PRE&gt;&lt;P&gt;Ofcourse, i can make a ACL entry that permits this traffic based on the Source Service, but i would like to know/investigate why this is happening.&amp;nbsp;&lt;BR /&gt;Am i right by saying that the above entry is a&amp;nbsp;&lt;U&gt;new&lt;/U&gt; TCP Connection with Source Port of 443?&lt;BR /&gt;I'm a bit clueless on where to start troubleshooting/capturing. Obviously it would be best to start at the source (the server) but if i would want to capture traffic there, what should i look at? Source Port 443 and some kind of TCP Syn filter or anything?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&lt;BR /&gt;I did a Wireshark capture on the source (LSPAPPAMD211). I waited for the access-list to get a new hit with tcp/443 as the source port. I checked that TCP connection in WireShark based on the destination port (random port number). I looked at it but i didn't see anything weird.&lt;BR /&gt;&lt;BR /&gt;If anyone has a idea why this traffic is generating hits on the any-any rule that would be great. I want to get rid of the any-any rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/investigate-new-tcp-connections-from-specific-port-https/m-p/3830398#M11540</guid>
      <dc:creator>Eric Snijders</dc:creator>
      <dc:date>2020-02-21T16:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Investigate new TCP connections from specific port (HTTPS)</title>
      <link>https://community.cisco.com/t5/network-security/investigate-new-tcp-connections-from-specific-port-https/m-p/3830722#M11541</link>
      <description>&lt;P&gt;hmm... here some of the tips you can you to see what is happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show conn 192.168.20.71&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;show local-host 192.168.20.71 or show local-host 192.168.20.71 brief&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;show service-policy flow tcp host 192.168.20.71 host 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 14:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/investigate-new-tcp-connections-from-specific-port-https/m-p/3830722#M11541</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-04-02T14:59:10Z</dc:date>
    </item>
  </channel>
</rss>

