<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Packet Capture - explaination? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415452#M306190</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Isnt the source/destination port mentioned right after the IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.235.5.31.&lt;STRONG&gt;38001&lt;/STRONG&gt; &amp;gt; 64.x.x.x.&lt;STRONG&gt;1194&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess that would mean that the 53 is the packet size?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is this output from? I am too used to looking captures through Wireshark even though I take captures on the ASA itself most of the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't say I know what the problem might be but if we are talking about UDP then naturally there is no actual connection forming/sync. Is there traffic both ways or is the UDP traffic one way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Jan 2014 20:24:16 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2014-01-07T20:24:16Z</dc:date>
    <item>
      <title>Packet Capture - explaination?</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415450#M306188</link>
      <description>&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Segoe UI'; font-size: 10pt;"&gt;1: 07:48:59.867249 0026.51d7.65c1 0025.4538.6b73 0x0800 95: 10.235.5.31.38001 &amp;gt; 64.x.x.x.1194:&amp;nbsp; [udp sum ok] udp 53 (DF) (ttl 62, id 0)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm troubleshooting an issue with a device that once installed is per their support supposed to create a tunnel over port 1194 to their cloud. I see traffic passing to and from this device to their address space including this port but it is all udp 53? Can someone explain this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Needless to say at this point the tunnel is not forming.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415450#M306188</guid>
      <dc:creator>Anthony.Herman</dc:creator>
      <dc:date>2019-03-12T03:26:08Z</dc:date>
    </item>
    <item>
      <title>Packet Capture - explaination?</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415451#M306189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;UDP53 is DNS lookups. Perhaps the vendors device is trying to perform name resolution to the cloud hostname. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 18:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415451#M306189</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2014-01-07T18:43:45Z</dc:date>
    </item>
    <item>
      <title>Packet Capture - explaination?</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415452#M306190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Isnt the source/destination port mentioned right after the IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.235.5.31.&lt;STRONG&gt;38001&lt;/STRONG&gt; &amp;gt; 64.x.x.x.&lt;STRONG&gt;1194&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess that would mean that the 53 is the packet size?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is this output from? I am too used to looking captures through Wireshark even though I take captures on the ASA itself most of the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't say I know what the problem might be but if we are talking about UDP then naturally there is no actual connection forming/sync. Is there traffic both ways or is the UDP traffic one way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 20:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415452#M306190</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-01-07T20:24:16Z</dc:date>
    </item>
    <item>
      <title>Packet Capture - explaination?</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415453#M306191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you are correct about the ports Jouni. I too have been spoiled by Wireshark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anthony- Can you do a packet tracer so we can see if/where it could be blocked on the ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 20:32:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415453#M306191</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2014-01-07T20:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Capture - explaination?</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415454#M306192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies guys. You are correct those are packet sizes and those are the ports. It turns out the device firmware was the cause of the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That capture was from a packet capture on 8.2 ASA. I didn't understand what the '53' was showing me until Jouni mentioned it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate the feedback.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 21:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-explaination/m-p/2415454#M306192</guid>
      <dc:creator>Anthony.Herman</dc:creator>
      <dc:date>2014-01-07T21:26:49Z</dc:date>
    </item>
  </channel>
</rss>

