cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
299
Views
0
Helpful
1
Replies

Cisco Logs Clarification

martynbeck
Level 1
Level 1

I would ask if anyone can clarify the difference between a "TCP Reset-I" and a "TCP Reset-O" as seen

in cisco pix connection teardown logs.

Investigation on the cisco site turns up -I is inside,

-O is outside.

I have conflicting explanations.

The first is that a reset-I is a connection reset initiated by the pix to the tcp conversation parties, because it sees something wrong with the packet conversation. The reset-O is a connection reset by resets being received by the pix from the tcp conversation parties.

The second is that the -I and -O relate to notional inside and outside values on the interfaces, with a Reset -I or -O being stated according to whether a reset was received from the either host on the higher or lower interface.

Is either explanation correct ??

rgds

Martyn Beck

Telewest Communications

1 Reply 1

scoclayton
Level 7
Level 7

Martyn,

The second definition you mentioned is correct. The PIX should never RST a connection that is passing through it - we just silently drop packets have "something wrong with the packet conversation."

Hope this helps.

Scott