<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question on Firewall Capture in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/question-on-firewall-capture/m-p/1652794#M604288</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have capture some data on teh firewall so that I can troubleshoot the problem I am having. Here is the output from the firewall capture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5: 13:07:45 .716775 802.1Q vlan#64 PO 10.150.254.80.137 &amp;gt; 10.150.254.127.137:&amp;nbsp;&amp;nbsp; udp 50&lt;/P&gt;&lt;P&gt;6: 13:07:45 .810048 802 1Q vlan#64 PO 10.150.254.80.137 &amp;gt; 10.150.254.127.137:&amp;nbsp;&amp;nbsp; udp 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the above mean? Does it mean that source 10.150.254.80 is trying to talk to 10.150.254.127 on port 137 which is netbios? If yes than what is the meaning of port udp 50 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or whether 10.150.254.80 is tyring to talk to 10.150.254.127 on port udp 50?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance will be really appreciated.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Tks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:04:32 GMT</pubDate>
    <dc:creator>kuldeep.kaur</dc:creator>
    <dc:date>2019-03-11T20:04:32Z</dc:date>
    <item>
      <title>Question on Firewall Capture</title>
      <link>https://community.cisco.com/t5/network-security/question-on-firewall-capture/m-p/1652794#M604288</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have capture some data on teh firewall so that I can troubleshoot the problem I am having. Here is the output from the firewall capture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5: 13:07:45 .716775 802.1Q vlan#64 PO 10.150.254.80.137 &amp;gt; 10.150.254.127.137:&amp;nbsp;&amp;nbsp; udp 50&lt;/P&gt;&lt;P&gt;6: 13:07:45 .810048 802 1Q vlan#64 PO 10.150.254.80.137 &amp;gt; 10.150.254.127.137:&amp;nbsp;&amp;nbsp; udp 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the above mean? Does it mean that source 10.150.254.80 is trying to talk to 10.150.254.127 on port 137 which is netbios? If yes than what is the meaning of port udp 50 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or whether 10.150.254.80 is tyring to talk to 10.150.254.127 on port udp 50?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance will be really appreciated.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Tks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-on-firewall-capture/m-p/1652794#M604288</guid>
      <dc:creator>kuldeep.kaur</dc:creator>
      <dc:date>2019-03-11T20:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Firewall Capture</title>
      <link>https://community.cisco.com/t5/network-security/question-on-firewall-capture/m-p/1652795#M604289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;10.150.254.80.137 &amp;gt; 10.150.254.127.137:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source ip 10.150.254.80 source port 137&lt;/P&gt;&lt;P&gt;destination ip 10.150.254.127 destination port 137&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;don't worry about the UDP 50.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that port is for netbios&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 22:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-on-firewall-capture/m-p/1652795#M604289</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-10T22:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Firewall Capture</title>
      <link>https://community.cisco.com/t5/network-security/question-on-firewall-capture/m-p/1652796#M604290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It means that source: 10.150.254.80, destination: 10.150.254.127, service: UDP/137 (Netbios), and and 50 is the size of the UDP packet (50 bytes).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 23:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-on-firewall-capture/m-p/1652796#M604290</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-03-10T23:06:59Z</dc:date>
    </item>
  </channel>
</rss>

