Solved

IPSEC Messages information

Posted on 2011-09-21
4
381 Views
Last Modified: 2012-08-13
Hi,

When i am connecting to a Cisco VPN server from my LAN PC through a ASA Firewall , I have the connection status from my PC to VPN server ,it shows athe following messages

"
SEZ-ODC5-Firewall# sh conn address 172.18.140.79
783 in use, 2924 most used
GRE outside 164.77.210.178:36096 inside 172.18.140.79:1723, idle 0:00:00, bytes
4173, flags E
TCP outside 164.77.210.178:1723 inside 172.18.140.79:53703, idle 0:00:00, bytes
560, flags UIO
UDP outside 164.77.210.178:500 inside 172.18.140.79:500, idle 0:01:38, bytes 158
4, flags -
GRE outside 164.77.210.178:1723 inside 172.18.140.79:25138, idle 0:00:00, bytes
2285, flags E
"

Waht are the Meaning of Source Ports to destination and how can i confirm is that system is connected to VPN server .

Ex: In the Following message take the First line :
GRE outside 164.77.210.178:36096 inside 172.18.140.79:1723, idle 0:00:00, bytes
4173, flags E

What is the line means from Source port 1723 to destintion port 36096.. What is the connection means

Regards
Ramu


 
0
Comment
Question by:RAMU CH
  • 2
  • 2
4 Comments
 
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 500 total points
ID: 36574056
Hi Ramu :)

port 1723 is used to establish a PPTP connection.
port 500 is for IKE (Internet Key Exchange) for authtentication.

The ports > 1023 are random ports where the is set up from.
0
 
LVL 1

Author Comment

by:RAMU CH
ID: 36574189
Hi Eriniebeek

1) What is the meaning of the following message :

TCP outside 164.77.210.178:1723 inside 172.18.140.79:53703, idle 0:00:00, bytes
560, flags UIO

2) What is the meaning og the following message :
GRE outside 164.77.210.178:1723 inside 172.18.140.79:25138, idle 0:00:00, bytes
2285, flags E

In the First message  from Source to destination TCP connection has formed with 1723(PPTP)
In the Second Message from Source to destination GRE connection has formed with 1723(PPTP).
here 164.77.210.178 is VPN server (PPTP server)
What is the difference between above two and what does it means.

3) What is the meaning og the following message :

UDP outside 164.77.210.178:500 inside 172.18.140.79:500, idle 0:01:38, bytes 158
4, flags -

From the above message Is IKE has  establsihed  or negotiating?
IS IKE traffic is a UDP traffic ? means a Phase-1 traffic


What are the meaning of the Flags :
UIO
E
-

Regards
ramu
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
ID: 36574315
What is the difference between above two and what does it means.
The two belong together. The TCP connecting is used to manage the tunnel through which the encrypted data flows. The GRE connection is the actual tunnel.

From the above message Is IKE has  establsihed  or negotiating?
IS IKE traffic is a UDP traffic ? means a Phase-1 traffic

It looks like it is finished (no flags) and is just waiting to time out. IKE is used to set up the security association (SA). Have a look at: http://en.wikipedia.org/wiki/Internet_Key_Exchange

And for the flags:

Flag     Description
U     up
f     inside FIN
F     outside FIN
r     inside acknowledged FIN
R     outside acknowledged FIN
s     awaiting outside SYN
S     awaiting inside SYN
M     SMTP data
H     HTTP get (not used)
T     TCP SIP connection
---     SKINNY (not used)
I     inbound data
O     outbound data
q     SQL*Net data
n     nailed connection (no supported)
d     dump
P     inside back connection
E     outside back connection
G     group
p     replicated (unused)
a     awaiting outside ACK to SYN
A     awaiting inside ACK to SYN
B     initial SYN from outside
R     RPC
H     H.323
T     UDP SIP connection
m     SIP media connection
t     SIP transient connection
D     DNS
0
 
LVL 1

Author Closing Comment

by:RAMU CH
ID: 36922416
Thanks
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VPN issue 2 60
DMVPN Spoke Connectivity Issue 1 26
Cisco 3650 switch 7 36
port redirection on cisco asa 5520 5 8
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question