cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9789
Views
0
Helpful
5
Replies

Cisco ASA "show conn" command

umeshunited
Level 1
Level 1

Hi All,

I have output of "show conn" command as below. How do I check which one is the originator of the traffic ?

 

TCP LAN_Users 10.149.10.11:50707 Mgmt 10.32.11.100:443, idle 0:00:03, bytes 1752, flags UIOB

5 Replies 5

Traffic initiated from mgmt to lan


@Mohammed al Baqari wrote:
Traffic initiated from mgmt to lan

Hi Mohammed,

 

How to identify which interface originated traffic ?

From Flags ? or Port numbers ?

Hi,

 

My guess it that it's lan to mgmt. Look at the ports.

If there are some ports for which you can't tell, search for the B flag (initial SYN from outside) and you'll get your answer (lower to higher if exists, higher to lower if missing).

 

Thanks,
Octavian

I also looked into this and I find it's a matter of reading flags, still I didn't find an easy way to read it.

Does it exist (this easy way) or it's a matter of experts with hundred of conn reading connections already on their belt?

Sorry to say, this answer is wrong. 

 

The traffic is from LAN to Management. Most of the time, the destination ports will be well-known ports and source ports will be random generated.

 

Thank you.

Review Cisco Networking for a $25 gift card