<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic flags sxaA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/flags-sxaa/m-p/2352630#M308323</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am gettig the below logs in one of my ASA when trying to access one destination IP. I have site to site VPN established from this firewall and have &lt;/P&gt;&lt;P&gt;193.244.75.128/25 added in VPN tunnel encryption. However I am blocking 193.244.75.200/32&amp;nbsp; through tunnel and sending over plain internet. This firewall is behind perimeter firewall. Usually NATing will be happening in perimeter firewall.Since i was not able to access this IP from the desktops which are behind this ODC firewall, I have placed NAT statements in ODC firewall and getting below Logs in ODC firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Xlate:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP PAT from inside:10.222.6.14/54436 to outside:203.99.192.210/54436 flags ri idle 0:00:15 timeout 0:00:30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP outside&amp;nbsp; 193.244.75.200:443 inside&amp;nbsp; 10.222.6.14:54436, idle 0:00:12, bytes 0, flags sxaA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Soumya&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:09:14 GMT</pubDate>
    <dc:creator>sayast001</dc:creator>
    <dc:date>2019-03-12T03:09:14Z</dc:date>
    <item>
      <title>flags sxaA</title>
      <link>https://community.cisco.com/t5/network-security/flags-sxaa/m-p/2352630#M308323</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am gettig the below logs in one of my ASA when trying to access one destination IP. I have site to site VPN established from this firewall and have &lt;/P&gt;&lt;P&gt;193.244.75.128/25 added in VPN tunnel encryption. However I am blocking 193.244.75.200/32&amp;nbsp; through tunnel and sending over plain internet. This firewall is behind perimeter firewall. Usually NATing will be happening in perimeter firewall.Since i was not able to access this IP from the desktops which are behind this ODC firewall, I have placed NAT statements in ODC firewall and getting below Logs in ODC firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Xlate:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP PAT from inside:10.222.6.14/54436 to outside:203.99.192.210/54436 flags ri idle 0:00:15 timeout 0:00:30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP outside&amp;nbsp; 193.244.75.200:443 inside&amp;nbsp; 10.222.6.14:54436, idle 0:00:12, bytes 0, flags sxaA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Soumya&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:09:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flags-sxaa/m-p/2352630#M308323</guid>
      <dc:creator>sayast001</dc:creator>
      <dc:date>2019-03-12T03:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: flags sxaA</title>
      <link>https://community.cisco.com/t5/network-security/flags-sxaa/m-p/3330183#M308324</link>
      <description>&lt;P&gt;This is an old thread, but for anyone that stumbles on it like I did, I found an answer for my own presentation of this odd behavior.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We took a wireshark, and the cipher specs were failing to negotiate for tcp/443 (https). This led to the sxaA flags showing up in the conn, and then quickly disappearing. Because the negotiation is so fast, it's hard to catch in that table.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;kyler&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2018 15:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/flags-sxaa/m-p/3330183#M308324</guid>
      <dc:creator>Kyler Middleton</dc:creator>
      <dc:date>2018-02-13T15:56:08Z</dc:date>
    </item>
  </channel>
</rss>

