Solved

ASA :How to see the connection status

Posted on 2011-09-21
10
704 Views
Last Modified: 2012-05-12
Hi

 How to findout the connection is establsished or not in a Firewall from Source to Destination using ASA Firewall(Assume NAT and access-list are  proper).What are the commands in ASA  can give the details about the connection) ,

Assume my Internal IP is 172.16.X.X
Public IP : 212.242.23.X
Accessing the Public IP using http (port 81) : http://212.242.23.X:81

how cani find the Connection is establshed or not through ASA Firewall

Regards
Ramu
0
Comment
Question by:RAMU CH
  • 5
  • 4
10 Comments
 
LVL 1

Author Comment

by:RAMU CH
Comment Utility
What does it means when giveing the command :

NEW-TCL-ILL-FW# sh conn address 115.111.228.36
9672 in use, 106426 most used

what does it means " 9672 in use, 106426 most used"

regards
ramu
0
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
Try 'show conn address 115.111.228.3 detailed'
That might give you some more info.
0
 
LVL 1

Author Comment

by:RAMU CH
Comment Utility
If i do the above suggested step the output is showling as below

NEW-TCL-ILL-FW# sh conn address 115.111.228.36 detail
7702 in use, 106426 most used
Flags: A - awaiting inside ACK to SYN, a - awaiting outside ACK to SYN,
       B - initial SYN from outside, C - CTIQBE media, D - DNS, d - dump,
       E - outside back connection, F - outside FIN, f - inside FIN,
       G - group, g - MGCP, H - H.323, h - H.225.0, I - inbound data,
       i - incomplete, J - GTP, j - GTP data, K - GTP t3-response
       k - Skinny media, M - SMTP data, m - SIP media, n - GUP
       O - outbound data, P - inside back connection, p - Phone-proxy TFTP conne
ction,
       q - SQL*Net data, R - outside acknowledged FIN,
       R - UDP SUNRPC, r - inside acknowledged FIN, S - awaiting inside SYN,
       s - awaiting outside SYN, T - SIP, t - SIP transient, U - up,
       V - VPN orphan, W - WAAS,
       X - inspected by service module

WHAT IS THE MEANING OF 7702 in use, 106426 most used

Regards
ramu
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 333 total points
Comment Utility
Please, NO SHOUTING
;)

Anyway, 7702 in use, 106426 most used means there are currently 7702 connections through the ASA and the maximum number of simultanious connections through the ASA since power on is 106426.
0
 
LVL 1

Author Comment

by:RAMU CH
Comment Utility
Hi Ernibeek,

u r always with me and sorry for troubling you with my useless questions but i dont have any source xcept you people as i already shared that i dont want to leave small info about Firewall /VPN as i want to be expertised in that

Regards
Ramu
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 333 total points
Comment Utility
No problem.

And by the way, there are no useless questions. Every time you learn something from asking those question means that they are useful, right?
0
 
LVL 1

Author Comment

by:RAMU CH
Comment Utility
Tks Erniebeek

Regards
Ramu
0
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
You're welcome.
It's always nice to encounter someone who is so eager to learn :)
0
 
LVL 5

Assisted Solution

by:Feroz Ahmed
Feroz Ahmed earned 167 total points
Comment Utility
Hi,

To see whether the connection is established successfully from Source to Destination on ASA firewall the command is as below :

ASA#"sh int ip brief" (This command will give you whether the connection between source and destination is established successfully or not).Once you type the command the outpt genereated should give you the ip address followed by status "Administratively up " and up if it is administratively down then it should be Administratively down to make it up one should check configuration .
0
 
LVL 1

Author Closing Comment

by:RAMU CH
Comment Utility
Thanks
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

How to configure Site to Site VPN on a Cisco ASA.     (version: 1.1 - updated August 6, 2009) Index          [Preface]   1.    [Introduction]   2.    [The situation]   3.    [Getting started]   4.    [Interesting traffic]   5.    [NAT0]   6.…
This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now