02-28-2017 09:26 PM - edited 03-12-2019 01:59 AM
Hi all!
I have following xlate cfg:
SD2-5-7-15-FW-5/vdc-ke# sh run all | i xlate
xlate per-session deny tcp any4 8.8.8.0 255.255.255.0
xlate per-session permit tcp any4 any4
xlate per-session permit tcp any4 any6
xlate per-session permit tcp any6 any4
xlate per-session permit tcp any6 any6
xlate per-session permit udp any4 any4 eq domain
xlate per-session permit udp any4 any6 eq domain
xlate per-session permit udp any6 any4 eq domain
xlate per-session permit udp any6 any6 eq domain
Do not analyze why and what for, it doesn't matter this time. The question is - how can I confirm and verify that multi-session works when I expect it to work? I do not see translation type in logs or any show commands.
02-28-2017 10:44 PM
hi,
issue the show xlate or show conn commands instead.
also use pipe "|" to have granular output.
02-28-2017 11:56 PM
mm.. show xlate does not make sense, but show conn detail does:
E-1-1-3-FW-61/vdc-dev# show conn detail
1806 in use, 22265 most used
Flags: A - awaiting inside ACK to SYN, a - awaiting outside ACK to SYN,
B - initial SYN from outside, b - TCP state-bypass or nailed,
C - CTIQBE media, c - cluster centralized,
D - DNS, d - dump, E - outside back connection, F - outside FIN, f - inside FIN,
G - group, g - MGCP, H - H.323, h - H.225.0, I - inbound data,
i - incomplete, J - GTP, j - GTP data, K - GTP t3-response
k - Skinny media, M - SMTP data, m - SIP media, n - GUP
O - outbound data, P - inside back connection, p - Phone-proxy TFTP connection,
q - SQL*Net data, R - outside acknowledged FIN,
R - UDP SUNRPC, r - inside acknowledged FIN, S - awaiting inside SYN,
s - awaiting outside SYN, T - SIP, t - SIP transient, U - up,
V - VPN orphan, W - WAAS,
X - inspected by service module,
x - per session, Y - director stub flow, y - backup stub flow,
Z - Scansafe redirection, z - forwarding stub flow
So where no 'x' flag, means it is multi-session translation.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide