Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
New Member

UDP traffic analyzed in L4 traffic monitor?

Dear all,

I just wonder if anyone knows whether UDP traffic is analyzed by the WSA's L4 traffic monitor?

It just tells "all ports" in the settings and reports also only reflect port numbers but no details like

which protocol (tcp/udp).




Everyone's tags (5)
Cisco Employee

Re: UDP traffic analyzed in L4 traffic monitor?

UDP ports will not be blocked.

The L4TM will use the T1 interface to detect traffic to destinations that are on its blacklist.  Once detected, the the data interface on the WSA will send a packet with the TCP reset flag to the client to prevent a TCP connection.

I have not tested this so someone correct me if I am wrong.  I am answering this based on my understanding of the L4TM feature, and how it works.  Since UDP is connectionless, there is no connection for it to kill.

Now this makes me wonder about the Monitor feature though.  But I am almost certain it will not block if the action is set to block.

I'll check this out when I'm in the office and will get back to you.


Cisco Employee

Re: UDP traffic analyzed in L4 traffic monitor?

I have confirmed that UDP traffic will not be blocked or monitored by the L4TM feature.  Only TCP.  Hope this helps.


Cisco Employee

I stand corrected now.  I

I stand corrected now.  The L4TM does indeed block/monitor TCP and UDP (even ICMP).  My previous test/setup were not valid.


CreatePlease login to create content