Personal Stateful Firewall Overview
Understanding Rules with Stateful Inspection ▀
Cisco ASR 5000 Series Product Overview ▄
OL-22938-02
table holds a list of information that identifies the subscriber session it represents. Generally this information includes
the source and destination IP address, flags, sequence, acknowledgement numbers, etc.
When a connection is permitted through the Personal Stateful Firewall enabled chassis, a state entry is created. If a
session connection with same information (source address, source port, destination address, destination port, protocol) is
requested the firewall subsystem compares the packet‘s information to the state table entry to determine the validity of
session. If the packet is currently in a table entry, it allows it to pass, otherwise it is dropped.
Transport and Network Protocols and States
Transport protocols have their connection‘s state tracked in various ways. Many attributes, including IP address and port
combination, sequence numbers, and flags are used to track the individual connection. The combination of this
information is kept as a hash in the state table.
TCP Protocol and Connection State
TCP is considered as a stateful connection-oriented protocol that has well defined session connection states. TCP tracks
the state of its connections with flags as defined for TCP protocol. The following table describes different TCP
connection states.
Table 94.
TCP Connection States
State Flag
Description
TCP (Establishing Connection)
CLOSED
A ―non-state‖ that exists before a connection actually begins.
LISTEN
The state a host is in waiting for a request to start a connection. This is the starting state of a TCP connection.
SYN-SENT
The time after a host has sent out a SYN packet and is waiting for the proper SYN-ACK reply.
SYN-RCVD
The state a host is in after receiving a SYN packet and replying with its SYN-ACK reply.
ESTABLISHED The state a host is in after its necessary ACK packet has been received. The initiating host goes into this state
after receiving a SYN-ACK.
TCP (Closing Connection)
FIN-WAIT-1
The state a connection is in after it has sent an initial FIN packet asking for a graceful termination of the TCP
connection.
CLOSE-WAIT
The state a host‘s connection is in after it receives an initial FIN and sends back an ACK to acknowledge the
FIN.
FIN-WAIT-2
The connection state of the host that has received the ACK response to its initial FIN, as it waits for a final FIN
from its connection peer.
LAST-ACK
The state of the host that just sent the second FIN needed to gracefully close the TCP connection back to the
initiating host while it waits for an acknowledgement.
Содержание ASR 5000 Series
Страница 1: ......
Страница 26: ......
Страница 48: ...New In Release 10 0 SCM Features Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 50: ......
Страница 58: ......
Страница 67: ...Product Service and Feature Licenses Default Licenses Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 68: ......
Страница 126: ......
Страница 138: ......
Страница 146: ......
Страница 218: ......
Страница 236: ......
Страница 356: ......
Страница 374: ......
Страница 422: ......
Страница 496: ......
Страница 572: ......
Страница 654: ......
Страница 700: ......
Страница 726: ......
Страница 784: ......
Страница 816: ......
Страница 839: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 841: ...Network Address Translation Overview How NAT Works Cisco ASR 5000 Series Product Overview OL 22938 02 ...
Страница 844: ......
Страница 906: ......
Страница 926: ......
Страница 942: ......
Страница 943: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 30 Technical Specifications ...
Страница 966: ......
Страница 967: ...Cisco ASR 5000 Series Product Overview OL 22938 02 Chapter 31 Safety Electrical and Environmental Certifications ...
Страница 972: ......