Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet

Page of 1214
 
3-70
思科 ASA 系列命令参考,命令
 
 3       show as-path-access-list  show auto-update 命令
  show asp drop
----------------------------------------------------------------
Name: connection-timeout
Connection timeout:
    This counter is incremented when a flow is closed because of the expiration of it's 
inactivity timer.
Recommendation:
    No action required.
Syslogs:
    302014, 302016, 302018, 302021
----------------------------------------------------------------
Name: conn-limit-exceeded
Connection limit exceeded:
    This reason is given for closing a flow when the connection limit has been 
exceeded.The connection limit is configured via the 'set connection conn-max' action 
command.
Recommendation:
    None.
Syslogs:
    201011
----------------------------------------------------------------
Name: tcp-fins
TCP FINs:
    This reason is given for closing a TCP flow when TCP FIN packets are received.
Recommendations:
    This counter will increment for each TCP connection that is terminated normally with 
FINs.
Syslogs:
    302014
----------------------------------------------------------------
Name: syn-timeout
SYN Timeout:
    This reason is given for closing a TCP flow due to expiry of embryonic timer.
Recommendations:
    If these are valid session which take longer to establish a connection increase the 
embryonic timeout.
Syslogs:
    302014
----------------------------------------------------------------
Name: fin-timeout
FIN Timeout:
    This reason is given for closing a TCP flow due to expiry of half-closed timer.
Recommendations:
    If these are valid session which take longer to close a TCP flow, increase the 
half-closed timeout.