Identifying Reasons for Session Close in NSM
NSM supports the log reason for the session
close feature. NSM displays the reason for session close so that you
can differentiate session creation messages from session close messages.
If you do not want the reason to display, you can explicitly configure
the device not to display the field. Table 1 lists the reasons for session close that NSM identifies. Any session
that cannot be identified is labeled OTHER.
Table 1: Session Closings
TCP FIN
|
TCP connection torn down because of FIN packet.
|
TCP RST
|
TCP connection torn down because of RST packet.
|
RESP
|
Special sessions, such as PING and DNS, close when response
is received.
|
ICMP
|
ICMP error received.
|
AGE OUT
|
Connection aged out normally.
|
ALG
|
ALG forced session close either because of error or other
reasons specific to that ALG.
|
NSRP
|
NSRP session close message received.
|
AUTH
|
Session closed because of authentication failure.
|
OTHER
|
Reason for close not identified.
|
Published: 2009-08-20