<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capture Output in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/capture-output/m-p/3368234#M961815</link>
    <description>&lt;P&gt;What does Push mean in this case I had never heard that term used.&amp;nbsp; The only reason I put it was push was because it was in another tread I had found.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Apr 2018 14:55:55 GMT</pubDate>
    <dc:creator>james.weatherman</dc:creator>
    <dc:date>2018-04-18T14:55:55Z</dc:date>
    <item>
      <title>Capture Output</title>
      <link>https://community.cisco.com/t5/network-security/capture-output/m-p/3368170#M961812</link>
      <description>&lt;P&gt;I am trying to read the capture output that I am getting.&amp;nbsp; I know that the S=Syn, A=Ack, P=Push (What does PUSH mean?) but what does a dot (.) and a F stand for.&amp;nbsp; I am using the command show cap capin to get the information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;116: 08:41:51.820514 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159159008 win 65280&lt;BR /&gt; 117: 08:41:51.820697 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.5.38.64959: P 2159168509:2159168689(180) ack 3968189402 win 23172&lt;BR /&gt; 118: 08:41:51.820727 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159160468 win 65280&lt;BR /&gt; 119: 08:41:51.820788 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.5.38.64959: . 2159168689:2159169969(1280) ack 3968189402 win 23172&lt;BR /&gt; 120: 08:41:51.820788 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.5.38.64959: P 2159169969:2159171091(1122) ack 3968189402 win 23172&lt;BR /&gt; 121: 08:41:51.820804 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.5.38.64959: P 2159171091:2159172371(1280) ack 3968189402 win 23172&lt;BR /&gt; 122: 08:41:51.821002 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.5.38.64959: P 2159172371:2159172530(159) ack 3968189402 win 23172&lt;BR /&gt; 123: 08:41:51.821048 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159162870 win 65280&lt;BR /&gt; 124: 08:41:51.821124 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159164309 win 65280&lt;BR /&gt; 125: 08:41:51.821292 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159165769 win 65280&lt;BR /&gt; 126: 08:41:51.821338 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.5.38.64959: . 2159172530:2159173810(1280) ack 3968189402 win 23172&lt;BR /&gt; 127: 08:41:51.821338 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.5.38.64959: P 2159173810:2159174850(1040) ack 3968189402 win 23172&lt;BR /&gt; 128: 08:41:51.821383 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159167229 win 65280&lt;BR /&gt; 129: 08:41:51.825930 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.9.223.54128: F 64380739:64380739(0) ack 1606964975 win 10076&lt;BR /&gt; 130: 08:41:51.825946 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.9.223.54101: F 2796087050:2796087050(0) ack 1225516994 win 14028&lt;BR /&gt; 131: 08:41:51.826007 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.9.223.54098: F 2302808906:2302808906(0) ack 2216340728 win 12033&lt;BR /&gt; 132: 08:41:51.826022 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.9.223.54100: F 2986425331:2986425331(0) ack 2874897291 win 15216&lt;BR /&gt; 133: 08:41:51.826037 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.9.223.54157: F 323375547:323375547(0) ack 1481009295 win 6456&lt;BR /&gt; 134: 08:41:51.826037 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.9.223.54105: F 3252855761:3252855761(0) ack 951598908 win 15949&lt;BR /&gt; 135: 08:41:51.840212 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.16.15.61245: . 1714258375:1714259114(739) ack 3096216603 win 5079&lt;BR /&gt; 136: 08:41:51.840227 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.16.15.61245: . 1714259114:1714259988(874) ack 3096216603 win 5079&lt;BR /&gt; 137: 08:41:51.840242 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.16.15.61245: . 1714259988:1714261268(1280) ack 3096216603 win 5079&lt;BR /&gt; 138: 08:41:51.840242 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.16.15.61245: P 1714261268:1714261288(20) ack 3096216603 win 5079&lt;BR /&gt; 139: 08:41:51.840441 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.16.15.61245: P 1714261288:1714262568(1280) ack 3096216603 win 5079&lt;BR /&gt; 140: 08:41:51.840578 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.16.15.61245: P 1714262568:1714262588(20) ack 3096216603 win 5079&lt;BR /&gt; 141: 08:41:51.840990 802.1Q vlan#2114 P0 10.28.39.93.443 &amp;gt; 10.28.16.15.61245: P 1714262588:1714262755(167) ack 3096216603 win 5079&lt;BR /&gt; 142: 08:41:51.855958 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159168689 win 65280&lt;BR /&gt; 143: 08:41:51.856431 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159171091 win 65280&lt;BR /&gt; 144: 08:41:51.856751 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159172530 win 65280&lt;BR /&gt; 145: 08:41:51.857331 802.1Q vlan#2114 P0 10.28.5.38.64959 &amp;gt; 10.28.39.93.443: . ack 2159174850 win 65280&lt;BR /&gt; 146: 08:41:51.858888 802.1Q vlan#2114 P0 10.28.16.15.61245 &amp;gt; 10.28.39.93.443: . ack 1714259988 win 65280&lt;BR /&gt; 147: 08:41:51.859086 802.1Q vlan#2114 P0 10.28.16.15.61245 &amp;gt; 10.28.39.93.443: . ack 1714261288 win 65280&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:38:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-output/m-p/3368170#M961812</guid>
      <dc:creator>james.weatherman</dc:creator>
      <dc:date>2020-02-21T15:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Capture Output</title>
      <link>https://community.cisco.com/t5/network-security/capture-output/m-p/3368213#M961813</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;The dot is an &lt;STRONG&gt;ACK&lt;/STRONG&gt; flag, and the F is a &lt;STRONG&gt;FIN, ACK&lt;/STRONG&gt; .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why don't you dump the capture to PCAP, it would be easier to read:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;copy /pcap capture:XXXX ftp://x.x.x.x/FOO.pcap&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 14:39:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-output/m-p/3368213#M961813</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2018-04-18T14:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Capture Output</title>
      <link>https://community.cisco.com/t5/network-security/capture-output/m-p/3368229#M961814</link>
      <description>&lt;P&gt;Man I had a full brain freeze I could not think of what the F was.&amp;nbsp; I knew that 3 way hand shake but completely went blank today.&amp;nbsp; Thank you.&amp;nbsp; I don't have a FTP server in the organization that I can use but working on getting one for other things so will just use it once the server team gets it build for me to try out the command you had in the reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 14:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-output/m-p/3368229#M961814</guid>
      <dc:creator>james.weatherman</dc:creator>
      <dc:date>2018-04-18T14:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Capture Output</title>
      <link>https://community.cisco.com/t5/network-security/capture-output/m-p/3368234#M961815</link>
      <description>&lt;P&gt;What does Push mean in this case I had never heard that term used.&amp;nbsp; The only reason I put it was push was because it was in another tread I had found.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 14:55:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-output/m-p/3368234#M961815</guid>
      <dc:creator>james.weatherman</dc:creator>
      <dc:date>2018-04-18T14:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Capture Output</title>
      <link>https://community.cisco.com/t5/network-security/capture-output/m-p/3368251#M961816</link>
      <description>&lt;P&gt;Take a look at the TCP RFC: &lt;A href="https://tools.ietf.org/html/rfc793" target="_blank"&gt;https://tools.ietf.org/html/rfc793&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;...page 46 under the send and receive commands is detail on the PUSH flag.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 15:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-output/m-p/3368251#M961816</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2018-04-18T15:06:04Z</dc:date>
    </item>
  </channel>
</rss>

