<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic it’s a UDP packet and in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430085#M238399</link>
    <description>&lt;P&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: 'PT Serif', Georgia, Times, 'Times New Roman', serif; font-size: 18px; line-height: 27.599998474121094px; background-color: rgb(242, 242, 242);"&gt;it’s a UDP packet and therefore is stateless &amp;amp; no flags &amp;nbsp;but if your traffic is tcp you can check based on flags.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 18 May 2014 17:06:30 GMT</pubDate>
    <dc:creator>ajay chauhan</dc:creator>
    <dc:date>2014-05-18T17:06:30Z</dc:date>
    <item>
      <title>sh conn flag -</title>
      <link>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430084#M238396</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i ran the command&lt;/P&gt;&lt;P&gt;ASA1# sh conn address 10.0.0.2&lt;BR /&gt;18 in use, 567 most used&lt;BR /&gt;UDP outside&amp;nbsp; 128.100.56.135:123 inside&amp;nbsp; 10.0.0.2:123, idle 0:01:01, bytes 21312, flags -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA1# sh conn address 10.0.0.2&lt;BR /&gt;22 in use, 567 most used&lt;BR /&gt;UDP outside&amp;nbsp; 128.100.56.135:123 inside&amp;nbsp; 10.0.0.2:123, idle 0:00:44, bytes 21360, flags -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA1# sh conn address 10.0.0.2&lt;BR /&gt;23 in use, 567 most used&lt;BR /&gt;UDP outside&amp;nbsp; 128.100.56.135:123 inside&amp;nbsp; 10.0.0.2:123, idle 0:00:53, bytes 21408, flags -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to understand what does flag -&amp;nbsp;&amp;nbsp; mean here?&lt;/P&gt;&lt;P&gt;is this show connection is established?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:12:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430084#M238396</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T04:12:46Z</dc:date>
    </item>
    <item>
      <title>it’s a UDP packet and</title>
      <link>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430085#M238399</link>
      <description>&lt;P&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: 'PT Serif', Georgia, Times, 'Times New Roman', serif; font-size: 18px; line-height: 27.599998474121094px; background-color: rgb(242, 242, 242);"&gt;it’s a UDP packet and therefore is stateless &amp;amp; no flags &amp;nbsp;but if your traffic is tcp you can check based on flags.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 May 2014 17:06:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430085#M238399</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2014-05-18T17:06:30Z</dc:date>
    </item>
    <item>
      <title>Hi Ajay, So UDP has no flag</title>
      <link>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430086#M238400</link>
      <description>&lt;P&gt;Hi Ajay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So UDP has no flag associated with it.&lt;/P&gt;&lt;P&gt;But i ran the command again still it shows&lt;/P&gt;&lt;P&gt;ASA1#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sh conn address 10.0.0.2&lt;BR /&gt;50 in use, 567 most used&lt;BR /&gt;UDP outside&amp;nbsp; 128.100.56.135:123 inside&amp;nbsp; 10.0.0.2:123, idle 0:00:54, bytes 24192, flags -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this command is there and my switch connected to ASA has no NTP sync yet.&lt;/P&gt;&lt;P&gt;does it mean that as long as switch is trying to reach NTP server via ASA this command will show up&lt;/P&gt;&lt;P&gt;under sh conn ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Sun, 18 May 2014 17:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430086#M238400</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2014-05-18T17:19:12Z</dc:date>
    </item>
    <item>
      <title>Mahesh,Your inside switch (10</title>
      <link>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430087#M238403</link>
      <description>&lt;P&gt;Mahesh,&lt;/P&gt;&lt;P&gt;Your inside switch (10.0.0.2) appears to be configured to get ntp from a source at 128.100.56.135 (somewhere beyond your outside interface).&lt;/P&gt;&lt;P&gt;As Ajay noted, a connectionless (sometimes referred to as stateless) protocol like UDP will not have the SYN, ACK, SYN-ACK, RST etc. states that would cause flags to be set in the ASA's connection table. It does, however, register as a flow through the ASA so the return traffic can be allowed in without having to be permitted by an access-list. Those flows are tracked in the connection table - a bit confusing since they're connectionless.&lt;/P&gt;&lt;P&gt;The count of those flows will increment as UDP packets (ntp queries in this case) flow outbound through the ASA. By default, those connection entries last 2 minutes before timing out and being removed from the connection table. (That default can be overriden though.)&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2014 00:15:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430087#M238403</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-19T00:15:52Z</dc:date>
    </item>
    <item>
      <title> Thanks Marvin for explaining</title>
      <link>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430088#M238405</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Marvin for explaining in more detail.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2014 00:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sh-conn-flag/m-p/2430088#M238405</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2014-05-19T00:47:33Z</dc:date>
    </item>
  </channel>
</rss>

