This procedure shows how to use CLI commands to view the asymmetric traffic flow statistics collected by the Network Security appliance.
Important
To avoid depleting system resources and degrading appliance performance, enable this feature only while you are collecting and viewing the statistics needed to investigate asymmetric flows in the network.
The Network Security appliance collects and displays statistics for SYN-only flows and non-SYN-only asymmetric flows separately. To conserve system resources, each list can store no more than 100 statistics. After a list is filled to capacity, the appliance stops collecting statistics for that type of flow. Statistics collection for the flow resumes after you refresh the cache. The refresh operation clears both lists even if only one of the lists is full. Enabling statistics collection also clears both lists.
To calculate the percentage of asymmetric flows, divide the count of asymmetric flows by the total flow count and multiply by 100.
Note
If the majority of incomplete three-way handshakes (SYN-only flows) in your network represent known valid activity, you may not want to include SYN-only flow counts in the calculation of the percentage of asymmetric flows.
The show smartvision event-track asym-flow stats command lists statistics for SYN-only and true asymmetric flows separately.
SYN-Only Flows (<n>/100)
Statistics collected for SYN-only flows. The number <n> is the number of unique SYN‑only flows tracked by the appliance, up to a maximum of 100. Flows in this section should be evaluated for indications of a SYN flood attack that consumes connection resources.
True Asym Flows (<n>/100)
Statistics collected for true asymmetric flows. The number <n> is the number of unique non-SYN-only asymmetric flows tracked by the appliance, up to a maximum of 100.
src_ip:src_port
The IP address and port number of the client.
dst_ip:dst_port
The IP address and port number of the server.
flow_state
The flow state of the source TCP port.
tcp_state
The state of the TCP destination port.
pkt_count
Number of packets in the flow.
flow_count
Number of unique occurrences of the flow.
Prerequisites
Admin, Analyst, or Operator access to the appliance.
Collection of asymmetric traffic statistics is enabled.
Log in to the appliance CLI and go to enable mode.
hostname > enable
View the collected asymmetric traffic flow statistics:
hostname # show smartvision event-track asym-flow stats SYN-Only Flows (1/100): flow_ tcp_ pkt_ flow_ src_ip:src_port -- dst_ip:dst_port state state count count 145.254.160.237:3372 -- 65.208.228.223:80 new syn_sent 1 1 True Asym Flows (2/100): flow_ tcp_ pkt_ flow_ src_ip:src_port -- dst_ip:dst_port state state count count 145.254.160.237:3372 -- 65.208.228.223:80 new syn_sent 16 1 145.254.160.237:3371 -- 216.239.59.99:80 new (null) 3 1