<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What does TCP FINs mean at the end of the log in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833181#M956196</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andre, this simply indicates the tcp three way hand chacke process did not complete in other words the wait time for a sync packet exceeded the 30 seconds forcing to terminate the connection by timeout.&lt;/P&gt;&lt;P&gt;I believe this could be caused by congestion-latency somewhere along the path causing retransmission between source and destination, or even latency at the destination server.. Im sure others may provide more insight.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this happening with a single destination client or several.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See message 302014  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Jan 2008 00:54:34 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2008-01-29T00:54:34Z</dc:date>
    <item>
      <title>What does TCP FINs mean at the end of the log</title>
      <link>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833180#M956195</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm troubleshooting a connection problem between a client (inside) and a server (outside). The client (139.96.216.21)  starting the TCP session to the  destination (121.42.244.12). Please have a look at attachement... What does the TCP FINs mean at the end and why is there a FIN Timeout at the end.... Thanks in advance, AndrÃ©&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833180#M956195</guid>
      <dc:creator>andre.harasim</dc:creator>
      <dc:date>2019-03-11T11:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: What does TCP FINs mean at the end of the log</title>
      <link>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833181#M956196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andre, this simply indicates the tcp three way hand chacke process did not complete in other words the wait time for a sync packet exceeded the 30 seconds forcing to terminate the connection by timeout.&lt;/P&gt;&lt;P&gt;I believe this could be caused by congestion-latency somewhere along the path causing retransmission between source and destination, or even latency at the destination server.. Im sure others may provide more insight.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this happening with a single destination client or several.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See message 302014  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2008 00:54:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833181#M956196</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-01-29T00:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: What does TCP FINs mean at the end of the log</title>
      <link>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833182#M956197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jorge, this happens only to this client which is within the subnet 139.96.216.0/24 and also located inside the firewall. Other clients, which are located in other countries but with them same setup (Firewall in front of the WAN connection), doesn't have this problem. I don't think that the problem is caused by congestion-latency, because the response time is ok (less then 100ms).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\rc3all&amp;gt;ping 121.42.244.12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pinging 121.42.244.12 with 32 bytes of data:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reply from 121.42.244.12: bytes=32 time=37ms TTL=121&lt;/P&gt;&lt;P&gt;Reply from 121.42.244.12: bytes=32 time=37ms TTL=121&lt;/P&gt;&lt;P&gt;Reply from 121.42.244.12: bytes=32 time=37ms TTL=121&lt;/P&gt;&lt;P&gt;Reply from 121.42.244.12: bytes=32 time=37ms TTL=121&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping statistics for 121.42.244.12:&lt;/P&gt;&lt;P&gt;    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),&lt;/P&gt;&lt;P&gt;Approximate round trip times in milli-seconds:&lt;/P&gt;&lt;P&gt;    Minimum = 37ms, Maximum = 37ms, Average = 37ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I only wanted to be sure that the TCP FIN timeout is not related to the firewall. I think this is because of the application which seems to be not responding!?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2008 01:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833182#M956197</guid>
      <dc:creator>andre.harasim</dc:creator>
      <dc:date>2008-01-29T01:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: What does TCP FINs mean at the end of the log</title>
      <link>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833183#M956198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is very well possible app related timeout-responce issue, I do not believe it is  firewall related as firewall is doint what is suppose to do when the TCP handchake is not fully completed thus closing the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2008 20:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833183#M956198</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-01-29T20:08:45Z</dc:date>
    </item>
    <item>
      <title> Hi, http://www.tcpipguide</title>
      <link>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833184#M956201</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.tcpipguide.com/free/t_TCPConnectionTermination-2.htm"&gt;http://www.tcpipguide.com/free/t_TCPConnectionTermination-2.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Pls refer this URL.Nice Explanation for TCP FIN ACK and connection termination process.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2014 07:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-does-tcp-fins-mean-at-the-end-of-the-log/m-p/833184#M956201</guid>
      <dc:creator>Tushar Barke</dc:creator>
      <dc:date>2014-07-15T07:23:12Z</dc:date>
    </item>
  </channel>
</rss>

