<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 0 Bytes packets seen on pix. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535718#M527908</link>
    <description>&lt;P&gt;I am seeing lot of 0 Bytes packets in 'Show connections" output of the pix. &lt;/P&gt;&lt;P&gt;Servers behind pix are internet web servers and firewall is internet firewall. &lt;/P&gt;&lt;P&gt;I belive 0 Bytes packets are threat, but not sure whether the packets are sent by the servers to the outside world or it is recieveing these 0 Bytes packets.&lt;/P&gt;&lt;P&gt;Few lines of "show conn | inc Bytes "&lt;/P&gt;&lt;P&gt;ntf01# sh conn | inc Bytes 0&lt;/P&gt;&lt;P&gt;TCP out 148.104.5.2:10714 in x.x.171.166:80 idle 0:04:30 Bytes 0 flags U&lt;/P&gt;&lt;P&gt;TCP out 64.8.58.90:12419 in x.x.171.166:80 idle 0:34:02 Bytes 0 flags U&lt;/P&gt;&lt;P&gt;TCP out 71.98.79.104:61346 in x.x.171.166:80 idle 0:14:24 Bytes 0 flags U&lt;/P&gt;&lt;P&gt;TCP out 64.8.58.90:12239 in x.x.171.166:80 idle 0:33:12 Bytes 0 flags U&lt;/P&gt;&lt;P&gt;TCP out 208.141.82.4:15729 in x.x.171.167:80 idle 0:23:35 Bytes 0 flags UB&lt;/P&gt;&lt;P&gt;TCP out 128.122.92.235:1343 in x.x.171.166:80 idle 0:01:58 Bytes 0 flags aB&lt;/P&gt;&lt;P&gt;TCP out 209.208.224.72:25 in x.x.133.178:3032 idle 0:01:26 Bytes 0 flags saA&lt;/P&gt;&lt;P&gt;TCP out 172.16.1.170:5024 in x.x.133.254:9369 idle 0:01:49 Bytes 0 flags saA&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:41:39 GMT</pubDate>
    <dc:creator>anand_prakash1</dc:creator>
    <dc:date>2020-02-21T08:41:39Z</dc:date>
    <item>
      <title>0 Bytes packets seen on pix.</title>
      <link>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535718#M527908</link>
      <description>&lt;P&gt;I am seeing lot of 0 Bytes packets in 'Show connections" output of the pix. &lt;/P&gt;&lt;P&gt;Servers behind pix are internet web servers and firewall is internet firewall. &lt;/P&gt;&lt;P&gt;I belive 0 Bytes packets are threat, but not sure whether the packets are sent by the servers to the outside world or it is recieveing these 0 Bytes packets.&lt;/P&gt;&lt;P&gt;Few lines of "show conn | inc Bytes "&lt;/P&gt;&lt;P&gt;ntf01# sh conn | inc Bytes 0&lt;/P&gt;&lt;P&gt;TCP out 148.104.5.2:10714 in x.x.171.166:80 idle 0:04:30 Bytes 0 flags U&lt;/P&gt;&lt;P&gt;TCP out 64.8.58.90:12419 in x.x.171.166:80 idle 0:34:02 Bytes 0 flags U&lt;/P&gt;&lt;P&gt;TCP out 71.98.79.104:61346 in x.x.171.166:80 idle 0:14:24 Bytes 0 flags U&lt;/P&gt;&lt;P&gt;TCP out 64.8.58.90:12239 in x.x.171.166:80 idle 0:33:12 Bytes 0 flags U&lt;/P&gt;&lt;P&gt;TCP out 208.141.82.4:15729 in x.x.171.167:80 idle 0:23:35 Bytes 0 flags UB&lt;/P&gt;&lt;P&gt;TCP out 128.122.92.235:1343 in x.x.171.166:80 idle 0:01:58 Bytes 0 flags aB&lt;/P&gt;&lt;P&gt;TCP out 209.208.224.72:25 in x.x.133.178:3032 idle 0:01:26 Bytes 0 flags saA&lt;/P&gt;&lt;P&gt;TCP out 172.16.1.170:5024 in x.x.133.254:9369 idle 0:01:49 Bytes 0 flags saA&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535718#M527908</guid>
      <dc:creator>anand_prakash1</dc:creator>
      <dc:date>2020-02-21T08:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: 0 Bytes packets seen on pix.</title>
      <link>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535719#M527909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Anand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connections that are initiated from the outside will be displayed with a "B" flag.  In the output you have given, only two of the connections have the B flag.  The rest of them have been initiated from your inside hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps - pls rate the post if it does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paresh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2006 05:32:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535719#M527909</guid>
      <dc:creator>pkhatri</dc:creator>
      <dc:date>2006-02-06T05:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: 0 Bytes packets seen on pix.</title>
      <link>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535720#M527910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paresh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I run capture on the interface on which servers showing U flag are connected, but the capture shows the first SYN from outside host.There are no initial SYN seen on firewall interface from server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2006 09:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535720#M527910</guid>
      <dc:creator>anand_prakash1</dc:creator>
      <dc:date>2006-02-06T09:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: 0 Bytes packets seen on pix.</title>
      <link>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535721#M527911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That doesn't indicate 0 byte packets - which would be impossible.  It does indicate how many bytes have been transferred over that established (or even "un-established" saA) connection.  Get used to understanding the direction of your traffic (see link below).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also recommend you get familiar with syslog - instead of using the cli to analyze connections - as it can be frustrating trying to keep track of those that open and close often and quickly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/s.htm#wp1187542" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/s.htm#wp1187542&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2006 22:04:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-bytes-packets-seen-on-pix/m-p/535721#M527911</guid>
      <dc:creator>rsommer</dc:creator>
      <dc:date>2006-02-06T22:04:52Z</dc:date>
    </item>
  </channel>
</rss>

