cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
634
Views
0
Helpful
1
Replies

Output from the ASA sho conn command

I need some information about the output from the sho conn command on my ASA 5506-X.

 

The output looks like 

 

TCP outside: 64.74.17.129/443 (64.74.17.129/443) inside_2: 192.168.1.10/57595 (62.128.198.254/57595), flags UxIO , idle 11s, uptime 2D23h, timeout 1h0m, bytes 590417, xlate id 0x2aaabc0a0f80

Can anyone tell me what the ip/port numbers in the () mean?

 

For example: 64.74.17.129/443 (64.74.17.129/443)

 

1 Reply 1

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

That shows a NAT translation. The numbers in the brakcets are post-translation.

 

 

64.74.17.129/443 (64.74.17.129/443)  is the Global-local and (Global-outside)

 

192.168.1.10/57595 (62.128.198.254/57595) is Inside-local and (Inside-outside)

 

Ie, the inside IP 192.168.1.10 has been translated to the outside interface 62.128.198.254 using dynamic NAT

 

cheers,

Seb.

 

https://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/4606-8.html

Review Cisco Networking for a $25 gift card