<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix &amp;quot;Capture&amp;quot; output help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763826#M531561</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No Problem Mike &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Sep 2011 09:07:56 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2011-09-08T09:07:56Z</dc:date>
    <item>
      <title>Pix "Capture" output help</title>
      <link>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763821#M531556</link>
      <description>&lt;P&gt;Hello Everyone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone help me with understanding part of the output from a "capture",&amp;nbsp; taken from a PIx.&amp;nbsp; I have removed part of this output in order to fit it nicely onto the screen. But I need to undertsand what the letters "S" and "R" stand for, located in a column almost central to the output..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;04:12:35.091029 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: &lt;STRONG&gt;S&lt;/STRONG&gt; 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp 04:12:35.340085 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: S 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp 04:12:35.939785 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: S 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp 04:12:36.939679 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: S 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp 04:12:38.123666 155.131.30.28.3923 &amp;gt; 155.136.225.19.2144: S 3053111351:3053111351(0) win 32768 &amp;lt;mss 1380,nop,wscale 0,nop,nop,timestamp[|tcp]04:12:38.164160 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: &lt;STRONG&gt;S&lt;/STRONG&gt; 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp 04:12:38.939877 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: S 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp &lt;BR /&gt;04:12:41.391947 155.131.30.28.3923 &amp;gt; 155.136.225.19.2144: S 3053111351:3053111351(0) win 32768 &amp;lt;mss 1380,nop,wscale 0,nop,nop,timestamp[|tcp]04:12:41.431755 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: S 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp 04:12:42.939862 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: S 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp 04:12:44.670558 155.131.30.28.3923 &amp;gt; 155.136.225.19.2144: S 3053111351:3053111351(0) win 32768 &amp;lt;mss 1380,sackOK,eol&amp;gt;&lt;BR /&gt;04:12:44.710473 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: S 30113069:30113069(0) ack 3053111352 win 5792 &amp;lt;mss 1460,sackOK,timestamp 04:12:47.946377 155.131.30.28.3923 &amp;gt; 155.136.225.19.2144: &lt;STRONG&gt;R &lt;/STRONG&gt;3053111352:3053111352(0) win 0&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763821#M531556</guid>
      <dc:creator>thstagman</dc:creator>
      <dc:date>2019-03-11T21:21:50Z</dc:date>
    </item>
    <item>
      <title>Pix "Capture" output help</title>
      <link>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763822#M531557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These captures indicate a tcp handshake being taken place between the source and the destination. TCP handshake is a 3 way process, th source sends a SYN packet (S) and the destination replies that by SYN ACK, the source would again send an acknowledgement for it as ACK , and then the connection is established. If you see a R , it means that one of the machines sent a Reset to the connection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;04:12:47.946377 155.131.30.28.3923 &amp;gt; 155.136.225.19.2144: &lt;STRONG&gt;R &lt;/STRONG&gt;3053111352:3053111352(0) win 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see 155.131.30.28 sent a reset to 155.136.225.19, and the connection is terminated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are working with captures for the first time, my advise would be to use pcap format of captures and view them in wireshark. they would make it more simpler for you to understand and interpret. Here is a very good doc for it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-17814"&gt;https://supportforums.cisco.com/docs/DOC-17814&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this was helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 09:00:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763822#M531557</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-08T09:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: Pix "Capture" output help</title>
      <link>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763823#M531558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So much for me keeping it nice and tidy ...&amp;nbsp;&amp;nbsp; I have highlighted the letters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;04:12:44.710473 155.136.225.19.2144 &amp;gt; 155.131.30.28.3923: &lt;STRONG&gt;S&lt;/STRONG&gt; 30113069:30113069(0) ack 3053111352 win 5792 &lt;MSS 1460=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;04:12:47.946377 155.131.30.28.3923 &amp;gt; 155.136.225.19.2144: &lt;STRONG&gt;R&lt;/STRONG&gt; 3053111352:3053111352(0) win 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 09:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763823#M531558</guid>
      <dc:creator>thstagman</dc:creator>
      <dc:date>2011-09-08T09:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Pix "Capture" output help</title>
      <link>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763824#M531559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks, that has helped me a great deal ,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the best to you ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 09:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763824#M531559</guid>
      <dc:creator>thstagman</dc:creator>
      <dc:date>2011-09-08T09:03:00Z</dc:date>
    </item>
    <item>
      <title>Pix "Capture" output help</title>
      <link>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763825#M531560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can see it in here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The machine 155.136.225.19 sent the other machine (155.131.30.28) requesting a connection with a SYN packet (S), the other machine did not acknowledge it and sent a termination for it or reset (R).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 09:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763825#M531560</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-08T09:05:23Z</dc:date>
    </item>
    <item>
      <title>Pix "Capture" output help</title>
      <link>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763826#M531561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No Problem Mike &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 09:07:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-quot-capture-quot-output-help/m-p/1763826#M531561</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-08T09:07:56Z</dc:date>
    </item>
  </channel>
</rss>

