cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2641
Views
15
Helpful
4
Replies

ASA show connection all question

i.leridant
Level 1
Level 1

Hello everyone,

 

I was wondering one thing : in an ASA I enter this command => show conn all

I have a lot of connections, more than 200.

Some are idle since 1s and others are idle since 300 hours.

My question is : this command shows the active connections only (so I have one user connected since more than 300 hours) or does it show connections since a certain amout of time, if so since how long ?

 

Best regards,

Irwin

1 Accepted Solution

Accepted Solutions

Pulkit Saxena
Cisco Employee
Cisco Employee

Hi Irwin,

 

Here is a link which explains about "show conn" :

https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s4.html#pgfId-1437635

Now since you ran, "show conn all" -- Displays connections that are to the device or from the device, in addition to through-traffic connections.

 

So basically the default "show conn" only shows through-the-box connections and with "show conn all", you will be seeing the management connections as well.

 

Now as per your statement, ideally you should not be seeing an idle connection for 300 hours, as per the default configuration, unless you have made some change via the MPF, you can check the default timeout settings, via the command, "show run timeout".

 

To your question, yes this command will show all active and idle connections which are not yet torn down.

 

Hope this was helpful.

 

Regards,

Pulkit

View solution in original post

4 Replies 4

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

   One difference that i'm aware of is that with "show conn all" you also see to the box sessions, like IKE/ESP tunnels terminated on the ASA, SSH/SNMP management sessions on the ASA, IGP/BGP adjacencies, ICMP.

 

Regards,

Cristian Matei.

By default connections through the ASA have an idle timeout of 1 hour after which the connection is torn down. But if there is constant traffic going from a program or app on the user's PC the connection will never be torn down unless the traffic stops or you as the administrator of the firewall clear the connection and / or block the traffic.

--
Please remember to select a correct answer and rate helpful posts

Pulkit Saxena
Cisco Employee
Cisco Employee

Hi Irwin,

 

Here is a link which explains about "show conn" :

https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s4.html#pgfId-1437635

Now since you ran, "show conn all" -- Displays connections that are to the device or from the device, in addition to through-traffic connections.

 

So basically the default "show conn" only shows through-the-box connections and with "show conn all", you will be seeing the management connections as well.

 

Now as per your statement, ideally you should not be seeing an idle connection for 300 hours, as per the default configuration, unless you have made some change via the MPF, you can check the default timeout settings, via the command, "show run timeout".

 

To your question, yes this command will show all active and idle connections which are not yet torn down.

 

Hope this was helpful.

 

Regards,

Pulkit

Thank you for your answer !