I have seen following output, but what is the difference between UB
vs UIOB
vs UIO
?
I looked at this website, and it has nice explanation, but I am having a hard time to decode it in context: https://www.tunnelsup.com/understanding-cisco-asa-connection-flags/
fw/pri/act# sh conn
21 in use, 600 most used
TCP ext_dmz 10.5.8.40:33882 int_dmz 10.5.16.39:9090, idle 0:06:17, bytes 0, flags UB
TCP ext_dmz 10.5.8.40:60713 int_dmz 10.5.16.39:9090, idle 0:00:03, bytes 561603, flags UIOB
TCP ext_dmz 10.5.8.39:5432 int_dmz 10.5.16.40:53600, idle 0:00:06, bytes 44857, flags UIO
TCP outside 10.5.255.3:57229 inside 65.194.212.101:22, idle 0:00:45, bytes 395449, flags UIOB
Best Answer
Cisco maintains many documents, and all you need to do is search. For example, ASA TCP Connection Flags (Connection Build-Up and Teardown):
To understand what the flags represent, you need to understand TCP handshaking and connections. If you understand this about TCP, then it is easy to interpret the state of the connection. For example, the
UB
flags for a connection means that the connection has received an inbound ACK.