cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1075
Views
0
Helpful
2
Replies

Cisco ASA Packet Capture

nitish14351
Level 1
Level 1

When I was troubleshooting connection between two host, ASA is between them . I got below packet capture :

 

1: 20:22:10.640897 125.62.z.z.63911 > 115.112.x.x.1720: S 4238196124:4238196124(0) win 5840 <mss 1460,sackOK,timestamp 171694205 0,nop,wscale 5>
2: 20:22:10.715691 115.112.x.x.1720 > 125.62.z.z.63911: S 2122443535:2122443535(0) ack 4238196125 win 14600 <mss 1380,nop,nop,sackOK>
3: 20:22:10.716912 125.62.z.z.63911 > 115.112.x.x.1720: . ack 2122443536 win 5840
4: 20:22:11.302962 125.62.z.z.63911 > 115.112.x.x.1720: P 4238196125:4238196637(512) ack 2122443536 win 5840
5: 20:22:11.303008 125.62.z.z.63911 > 115.112.x.x.1720: P 4238196637:4238197123(486) ack 2122443536 win 5840
6: 20:22:11.303481 115.112.x.x.1720 > 125.62.z.z.63911: . ack 4238196637 win 14088
7: 20:22:11.303481 115.112.x.x.1720 > 125.62.z.z.63911: . ack 4238197123 win 13602
8: 20:22:11.489781 115.112.x.x.1720 > 125.62.z.z.63911: P 2122443536:2122443609(73) ack 4238197123 win 15968
9: 20:22:11.490056 125.62.z.z.63911 > 115.112.x.x.1720: . ack 2122443609 win 5840
10: 20:22:11.490178 115.112.x.x.1720 > 125.62.z.z.63911: P 2122443609:2122443660(51) ack 4238197123 win 15968
11: 20:22:11.490178 115.112.x.x.1720 > 125.62.z.z.63911: F 2122443660:2122443660(0) ack 4238197123 win 15968
12: 20:22:11.490376 125.62.z.z.63911 > 115.112.x.x.1720: . ack 2122443660 win 5840
13: 20:22:11.502003 125.62.z.z.63911 > 115.112.x.x.1720: P 4238197123:4238197180(57) ack 2122443661 win 5840
14: 20:22:11.502171 115.112.x.x.1720 > 125.62.z.z.63911: . ack 4238197180 win 15911
15: 20:22:11.502323 125.62.z.z.63911 > 115.112.x.x.1720: F 4238197180:4238197180(0) ack 2122443661 win 5840
16: 20:22:11.502461 115.112.x.x.1720 > 125.62.128.175.63911: . ack 4238197181 win 15911

 

 

Which I was unable to understand. Can anyone tell me what these means. Thanks in Advance

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Not enough information to give you an answer.

You only shared a high level packet summary showing two way communications between two hosts using port 1720 (commonly used for H.323 videoconferencing).

Please explain this deeply
Review Cisco Networking for a $25 gift card