<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX syslog message PIX-6-302002 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-syslog-message-pix-6-302002/m-p/97852#M679179</link>
    <description>&lt;P&gt;IN the PIX documentation it doesnt give any guidelines as to what the flags on the  end of the message mean. In the syslog message below. The tcp session is reset and any packets following this are denied because of no connection in connection table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 12 08:59:44 pixfw %PIX-6-302002: Teardown TCP connection 30269612 faddr 196.8.107.24/443 gaddr 196.26.139.246/56873 laddr 10.2.2.111/56873 duration 0:00:01 bytes 2870 (TCP Reset-I)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like to know is which side initiated the tcp reset. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 05:58:48 GMT</pubDate>
    <dc:creator>jerryd</dc:creator>
    <dc:date>2020-02-21T05:58:48Z</dc:date>
    <item>
      <title>PIX syslog message PIX-6-302002</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-message-pix-6-302002/m-p/97852#M679179</link>
      <description>&lt;P&gt;IN the PIX documentation it doesnt give any guidelines as to what the flags on the  end of the message mean. In the syslog message below. The tcp session is reset and any packets following this are denied because of no connection in connection table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 12 08:59:44 pixfw %PIX-6-302002: Teardown TCP connection 30269612 faddr 196.8.107.24/443 gaddr 196.26.139.246/56873 laddr 10.2.2.111/56873 duration 0:00:01 bytes 2870 (TCP Reset-I)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like to know is which side initiated the tcp reset. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-message-pix-6-302002/m-p/97852#M679179</guid>
      <dc:creator>jerryd</dc:creator>
      <dc:date>2020-02-21T05:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX syslog message PIX-6-302002</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-message-pix-6-302002/m-p/97853#M679182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is an unofficial list of PIX connection flags:&lt;/P&gt;&lt;P&gt;U   | up  &lt;/P&gt;&lt;P&gt;f   | inside FIN  &lt;/P&gt;&lt;P&gt;F   | outside FIN &lt;/P&gt;&lt;P&gt;r   | inside acknowledged FIN &lt;/P&gt;&lt;P&gt;R   | outside acknowledged FIN &lt;/P&gt;&lt;P&gt;s   | awaiting outside SYN &lt;/P&gt;&lt;P&gt;S   | awaiting inside SYN &lt;/P&gt;&lt;P&gt;M   | SMTP data  &lt;/P&gt;&lt;P&gt;H   | HTTP get (not used) &lt;/P&gt;&lt;P&gt;I   | inbound data  &lt;/P&gt;&lt;P&gt;O   | outbound data  &lt;/P&gt;&lt;P&gt;q   | SQL*Net data   &lt;/P&gt;&lt;P&gt;n   | nailed connection (no supported) &lt;/P&gt;&lt;P&gt;d   | dump      &lt;/P&gt;&lt;P&gt;P   | inside back connection&lt;/P&gt;&lt;P&gt;E   | outside back connection&lt;/P&gt;&lt;P&gt;G   | group &lt;/P&gt;&lt;P&gt;p   | replicated (unused) &lt;/P&gt;&lt;P&gt;a   | awaiting outside ACK to SYN &lt;/P&gt;&lt;P&gt;A   | awaiting inside ACK to SYN &lt;/P&gt;&lt;P&gt;B   | initial SYN from outside &lt;/P&gt;&lt;P&gt;R   | RPC       &lt;/P&gt;&lt;P&gt;H   | H.323     &lt;/P&gt;&lt;P&gt;D   | DNS   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About a year ago I was told that pix flags will be documented on CCO, but I don't think that has been done yet. Anyway the list above covers most of the flags displayed when issueing a "show connection" command.&lt;/P&gt;&lt;P&gt;I'd recommend contacting TAC about this issue.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mustafa Hussein&lt;/P&gt;&lt;P&gt;Comark, Inc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2002 19:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-message-pix-6-302002/m-p/97853#M679182</guid>
      <dc:creator>mhussein</dc:creator>
      <dc:date>2002-02-12T19:32:37Z</dc:date>
    </item>
  </channel>
</rss>

