Help with "sho conn" flag (PIX 7.x)

Hello,

I'm hoping someone here can help me figure what might be happening here.
Source folks initiate a telnet session and they're saying they see the
packets go out on their FW, but unable to make a connection. On my FW, I do
a "sho conn", and I see the connection but it shows a "UB" flag.

The command reference guide shows:

U : Up
B : initial SYN from outside

Could someone help me determine what this might mean?

Thanks!
Jon Doe [ Mi, 14 März 2007 00:46 ] [ ID #1656738 ]

Re: Help with "sho conn" flag (PIX 7.x)

"Jon Doe" <jdoe [at] comcast.net> wrote in message
news:eoSdnX9Us8-KpWrYnZ2dnUVZ_g6dnZ2d [at] comcast.com...
>
> Hello,
>
> I'm hoping someone here can help me figure what might be happening here.
> Source folks initiate a telnet session and they're saying they see the
> packets go out on their FW, but unable to make a connection. On my FW, I
> do a "sho conn", and I see the connection but it shows a "UB" flag.
>
> The command reference guide shows:
>
> U : Up
> B : initial SYN from outside
>
> Could someone help me determine what this might mean?
>
> Thanks!

If you are seeing the connection on your firewall then it looks good. Try
snooping the traffic on the server that they are telneting to. Can that
server reply to the host? Does it have it's default gateway set?

Chris.
Chris [ Mi, 14 März 2007 22:34 ] [ ID #1657885 ]

Re: Help with "sho conn" flag (PIX 7.x)

chris wrote:

> If you are seeing the connection on your firewall then it looks good. Try
> snooping the traffic on the server that they are telneting to. Can that
> server reply to the host? Does it have it's default gateway set?

or a route back to the source?
do you have a route back to the server?
is the server replying to clients in its own LAN?


M
Mak [ Mo, 19 März 2007 17:13 ] [ ID #1662408 ]
Miscellaneous » comp.security.firewalls » Help with "sho conn" flag (PIX 7.x)

Vorheriges Thema: Brand-new Hosts file - will nail all the ads, spyware, improve your bandwidth, etc.....
Nächstes Thema: Someone Help Me With My PGP Firewall!!!