<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Tad, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/session-disconnected-duration-0-bytes-0/m-p/3064401#M134714</link>
    <description>&lt;P&gt;Hi Tad,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There can be multiple reasons behind this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;May I know what type of application is this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We need to take the interface and asp drop captures for this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, share a packet tracer output for this traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;I&gt;Regards,&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;I&gt;Aditya&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;I&gt;Please rate helpful posts and mark correct answers.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2017 08:21:26 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2017-06-15T08:21:26Z</dc:date>
    <item>
      <title>Session disconnected - duration 0 Bytes 0</title>
      <link>https://community.cisco.com/t5/network-security/session-disconnected-duration-0-bytes-0/m-p/3064400#M134712</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;While testing an application, we found that the session between the our virtual IP, and the backend server,&amp;nbsp; is established over the firewall, and disconnected immediately. So the connection log shows "duration 0:00:00 bytes 0 TCP FINs" (attached)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This basically tells us that NO data was sent over, or the packet received by the backend server was discarded.&lt;/P&gt;
&lt;P&gt;But when I do a telnet to the application server port, the telnet session is established and is successful.&lt;/P&gt;
&lt;P&gt;Why so? We were not able to pin point.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any inputs that could help me here please.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:35:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/session-disconnected-duration-0-bytes-0/m-p/3064400#M134712</guid>
      <dc:creator>tad.190804</dc:creator>
      <dc:date>2019-03-12T09:35:20Z</dc:date>
    </item>
    <item>
      <title>Hi Tad,</title>
      <link>https://community.cisco.com/t5/network-security/session-disconnected-duration-0-bytes-0/m-p/3064401#M134714</link>
      <description>&lt;P&gt;Hi Tad,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There can be multiple reasons behind this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;May I know what type of application is this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We need to take the interface and asp drop captures for this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, share a packet tracer output for this traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;I&gt;Regards,&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;I&gt;Aditya&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;I&gt;Please rate helpful posts and mark correct answers.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 08:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/session-disconnected-duration-0-bytes-0/m-p/3064401#M134714</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-06-15T08:21:26Z</dc:date>
    </item>
    <item>
      <title>Hi Tad,</title>
      <link>https://community.cisco.com/t5/network-security/session-disconnected-duration-0-bytes-0/m-p/3064402#M134716</link>
      <description>&lt;P&gt;Hi Tad,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The log is from ASDM I believe.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In order to troubleshoot the better approach is to apply captures on ASA for source and destination.&lt;/P&gt;
&lt;P&gt;If you want, I can help with the required commands but you need to be aware about the topolgy from ASA's perspactive.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please do run a packet tracer ase well.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now coming to your question that why it allow a telnet connection. It is fairly simple that on ASA Telnet traffic might have been allowed by any access rule but for normal traffic of that application, there is no rule to allow traffic and thats why the traffic is getting dropped. (It might be a reason, &amp;nbsp;not sure.)&lt;/P&gt;
&lt;P&gt;Its better we take the capture and packet tracer.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Br&lt;/P&gt;
&lt;P&gt;Dubey, Shivam&lt;/P&gt;
&lt;P&gt;Ex-TAC (shivdube)&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 11:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/session-disconnected-duration-0-bytes-0/m-p/3064402#M134716</guid>
      <dc:creator>er.shivamdubey31190</dc:creator>
      <dc:date>2017-06-15T11:18:21Z</dc:date>
    </item>
  </channel>
</rss>

