Solved

IPSEC Messages information

Posted on 2011-09-21
4
405 Views
Last Modified: 2012-08-13
Hi,

When i am connecting to a Cisco VPN server from my LAN PC through a ASA Firewall , I have the connection status from my PC to VPN server ,it shows athe following messages

"
SEZ-ODC5-Firewall# sh conn address 172.18.140.79
783 in use, 2924 most used
GRE outside 164.77.210.178:36096 inside 172.18.140.79:1723, idle 0:00:00, bytes
4173, flags E
TCP outside 164.77.210.178:1723 inside 172.18.140.79:53703, idle 0:00:00, bytes
560, flags UIO
UDP outside 164.77.210.178:500 inside 172.18.140.79:500, idle 0:01:38, bytes 158
4, flags -
GRE outside 164.77.210.178:1723 inside 172.18.140.79:25138, idle 0:00:00, bytes
2285, flags E
"

Waht are the Meaning of Source Ports to destination and how can i confirm is that system is connected to VPN server .

Ex: In the Following message take the First line :
GRE outside 164.77.210.178:36096 inside 172.18.140.79:1723, idle 0:00:00, bytes
4173, flags E

What is the line means from Source port 1723 to destintion port 36096.. What is the connection means

Regards
Ramu


 
0
Comment
Question by:RAMU CH
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 500 total points
ID: 36574056
Hi Ramu :)

port 1723 is used to establish a PPTP connection.
port 500 is for IKE (Internet Key Exchange) for authtentication.

The ports > 1023 are random ports where the is set up from.
0
 
LVL 1

Author Comment

by:RAMU CH
ID: 36574189
Hi Eriniebeek

1) What is the meaning of the following message :

TCP outside 164.77.210.178:1723 inside 172.18.140.79:53703, idle 0:00:00, bytes
560, flags UIO

2) What is the meaning og the following message :
GRE outside 164.77.210.178:1723 inside 172.18.140.79:25138, idle 0:00:00, bytes
2285, flags E

In the First message  from Source to destination TCP connection has formed with 1723(PPTP)
In the Second Message from Source to destination GRE connection has formed with 1723(PPTP).
here 164.77.210.178 is VPN server (PPTP server)
What is the difference between above two and what does it means.

3) What is the meaning og the following message :

UDP outside 164.77.210.178:500 inside 172.18.140.79:500, idle 0:01:38, bytes 158
4, flags -

From the above message Is IKE has  establsihed  or negotiating?
IS IKE traffic is a UDP traffic ? means a Phase-1 traffic


What are the meaning of the Flags :
UIO
E
-

Regards
ramu
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
ID: 36574315
What is the difference between above two and what does it means.
The two belong together. The TCP connecting is used to manage the tunnel through which the encrypted data flows. The GRE connection is the actual tunnel.

From the above message Is IKE has  establsihed  or negotiating?
IS IKE traffic is a UDP traffic ? means a Phase-1 traffic

It looks like it is finished (no flags) and is just waiting to time out. IKE is used to set up the security association (SA). Have a look at: http://en.wikipedia.org/wiki/Internet_Key_Exchange

And for the flags:

Flag     Description
U     up
f     inside FIN
F     outside FIN
r     inside acknowledged FIN
R     outside acknowledged FIN
s     awaiting outside SYN
S     awaiting inside SYN
M     SMTP data
H     HTTP get (not used)
T     TCP SIP connection
---     SKINNY (not used)
I     inbound data
O     outbound data
q     SQL*Net data
n     nailed connection (no supported)
d     dump
P     inside back connection
E     outside back connection
G     group
p     replicated (unused)
a     awaiting outside ACK to SYN
A     awaiting inside ACK to SYN
B     initial SYN from outside
R     RPC
H     H.323
T     UDP SIP connection
m     SIP media connection
t     SIP transient connection
D     DNS
0
 
LVL 1

Author Closing Comment

by:RAMU CH
ID: 36922416
Thanks
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question