Connection Flags on Cisco ASA
Below is presented list of flags with short description which you can see on Cisco devices:
A – awaiting inside ACK to SYN
a – awaiting outside ACK to SYN
B – initial SYN from outside
b – TCP state-bypass or nailed
C – CTIQBE media
D – DNS
d – dump
E – outside back connection
F – outside FIN
f – inside FIN
G – group
g – MGCP
H – H.323
h – H.225.0
I – inbound data
i – incomplete
J – GTP
j – GTP data
K – GTP t3-response
k – Skinny media
M – SMTP data
m – SIP media
n – GUP
O – outbound data
P – inside back connection
p – Phone-proxy TFTP connection
q – SQL*Net data
R – outside acknowledged FIN
R – UDP SUNRPC
r – inside acknowledged FIN
S – awaiting inside SYN
s – awaiting outside SYN
T – SIP
t – SIP transient
U – up
V – VPN orphan
W – WAAS
X – inspected by service module
Note: When checking flags in connection table on firewall make sure you confirm communication
protocol. It’s displayed in first column. Below is example of two identical flags having different meaning
depending on protocol used:
Example of connection table :
UDP outside 125.209.93.83:0 dmz 94.236.50.225:5060, idle 0:00:00, bytes 0, flags ti
UDP outside 125.209.93.83:0 dmz 94.236.50.225:5060, idle 0:00:00, bytes 0, flags ti
UDP outside 125.209.93.83:0 dmz 94.236.50.225:31825, idle 0:00:00, bytes 0, flags mi
UDP outside 125.209.93.83:0 dmz 94.236.50.225:31824, idle 0:00:00, bytes 0, flags mi