Identifying Reasons for Session Close in NSM
NSM supports the log reason for the session close feature. NSM displays the reason for session close so that you can differentiate session creation messages from session close messages. If you do not want the reason to display, you can explicitly configure the device not to display the field. Table 29 lists the reasons for session close that NSM identifies. Any session that cannot be identified is labeled OTHER.
Table 29: Session Closings
TCP FIN | TCP connection torn down because of FIN packet. |
TCP RST | TCP connection torn down because of RST packet. |
RESP | Special sessions, such as PING and DNS, close when response is received. |
ICMP | ICMP error received. |
AGE OUT | Connection aged out normally. |
ALG | ALG forced session close either because of error or other reasons specific to that ALG. |
NSRP | NSRP session close message received. |
AUTH | Session closed because of authentication failure. |
OTHER | Reason for close not identified. |