Here is an unofficial list of PIX connection flags:
U | up
f | inside FIN
F | outside FIN
r | inside acknowledged FIN
R | outside acknowledged FIN
s | awaiting outside SYN
S | awaiting inside SYN
M | SMTP data
H | HTTP get (not used)
I | inbound data
O | outbound data
q | SQL*Net data
n | nailed connection (no supported)
d | dump
P | inside back connection
E | outside back connection
G | group
p | replicated (unused)
a | awaiting outside ACK to SYN
A | awaiting inside ACK to SYN
B | initial SYN from outside
R | RPC
H | H.323
D | DNS
About a year ago I was told that pix flags will be documented on CCO, but I don't think that has been done yet. Anyway the list above covers most of the flags displayed when issueing a "show connection" command.
I'd recommend contacting TAC about this issue.
Regards,
Mustafa Hussein
Comark, Inc.