The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing the asymmetric flow statistics using the CLI

Prev Next

This procedure shows how to use CLI commands to view the asymmetric traffic flow statistics collected by the Network Security appliance.

Important

To avoid depleting system resources and degrading appliance performance, enable this feature only while you are collecting and viewing the statistics needed to investigate asymmetric flows in the network.

The Network Security appliance collects and displays statistics for SYN-only flows and non-SYN-only asymmetric flows separately. To conserve system resources, each list can store no more than 100 statistics. After a list is filled to capacity, the appliance stops collecting statistics for that type of flow. Statistics collection for the flow resumes after you refresh the cache. The refresh operation clears both lists even if only one of the lists is full. Enabling statistics collection also clears both lists.

To calculate the percentage of asymmetric flows, divide the count of asymmetric flows by the total flow count and multiply by 100.

Note

If the majority of incomplete three-way handshakes (SYN-only flows) in your network represent known valid activity, you may not want to include SYN-only flow counts in the calculation of the percentage of asymmetric flows.

The show smartvision event-track asym-flow stats command lists statistics for SYN-only and true asymmetric flows separately.

SYN-Only Flows (<n>/100)

Statistics collected for SYN-only flows. The number <n> is the number of unique SYN‑only flows tracked by the appliance, up to a maximum of 100. Flows in this section should be evaluated for indications of a SYN flood attack that consumes connection resources.

True Asym Flows (<n>/100)

Statistics collected for true asymmetric flows. The number <n> is the number of unique non-SYN-only asymmetric flows tracked by the appliance, up to a maximum of 100.

src_ip:src_port

The IP address and port number of the client.

dst_ip:dst_port

The IP address and port number of the server.

flow_state

The flow state of the source TCP port.

tcp_state

The state of the TCP destination port.

pkt_count

Number of packets in the flow.

flow_count

Number of unique occurrences of the flow.

Prerequisites

  • Admin, Analyst, or Operator access to the appliance.

  • Collection of asymmetric traffic statistics is enabled.

To view asymmetric traffic flow statistics:
  1. Log in to the appliance CLI and go to enable mode.

    hostname > enable
  2. View the collected asymmetric traffic flow statistics:

    hostname # show smartvision event-track asym-flow stats
     
    SYN-Only Flows (1/100):                                flow_   tcp_      pkt_    flow_
              src_ip:src_port --         dst_ip:dst_port   state   state     count   count
     145.254.160.237:3372     -- 65.208.228.223:80         new     syn_sent  1       1
      
    True Asym Flows (2/100):                               flow_   tcp_      pkt_    flow_
              src_ip:src_port --         dst_ip:dst_port   state   state     count   count
     145.254.160.237:3372     -- 65.208.228.223:80         new     syn_sent  16      1
     145.254.160.237:3371     --  216.239.59.99:80         new     (null)    3       1