cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
816
Views
0
Helpful
3
Replies

match tcp flags in access-list?

Is there a way to match tcp flags in an access-list on an ASA, e.g.:

  match-any +syn +fin +rst

or

   match byte[13] eq 2

   match byte[13] eq 17

   match byte[13] eq 4

?

3 Replies 3

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Bradley,

No, that is done on an IOS setup.

The ASA as it;s a  stateful firewall by default do not need that setup, he will perform a deep packet inspection of the TCP flags without any configuration required for that.

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thanks, Julio.  I would like to filter, in order to reduce the amount of data captured by a packet-capture.  Not for security purposes.

For example, when debugging a problem, sometimes it helps to view all flows through an interface; but you don't want to see each packet of every flow.  Just seeing the start and end of each TCP flow would be very useful.

Hello Bradley,

Got your point but the answer is no.

The ASA will show you the entire connection, you cannot specify on an ACL wheter you want to match a RST or a SYN flag on a tcp session.

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card