Cisco Cisco ASA 5580 Adaptive Security Appliance Leaflet
3-70
思科 ASA 系列命令参考,S 命令
第 3 章 show as-path-access-list 至 show auto-update 命令
show asp drop
----------------------------------------------------------------
Name: connection-timeout
Connection timeout:
This counter is incremented when a flow is closed because of the expiration of it's
inactivity timer.
Recommendation:
No action required.
Syslogs:
302014, 302016, 302018, 302021
----------------------------------------------------------------
Name: conn-limit-exceeded
Connection limit exceeded:
This reason is given for closing a flow when the connection limit has been
exceeded.The connection limit is configured via the 'set connection conn-max' action
command.
Recommendation:
None.
Syslogs:
201011
----------------------------------------------------------------
Name: tcp-fins
TCP FINs:
This reason is given for closing a TCP flow when TCP FIN packets are received.
Recommendations:
This counter will increment for each TCP connection that is terminated normally with
FINs.
Syslogs:
302014
----------------------------------------------------------------
Name: syn-timeout
SYN Timeout:
This reason is given for closing a TCP flow due to expiry of embryonic timer.
Recommendations:
If these are valid session which take longer to establish a connection increase the
embryonic timeout.
Syslogs:
302014
----------------------------------------------------------------
Name: fin-timeout
FIN Timeout:
This reason is given for closing a TCP flow due to expiry of half-closed timer.
Recommendations:
If these are valid session which take longer to close a TCP flow, increase the
half-closed timeout.