cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
821
Views
0
Helpful
3
Replies

UDP traffic analyzed in L4 traffic monitor?

info0000368
Level 1
Level 1

Dear all,

I just wonder if anyone knows whether UDP traffic is analyzed by the WSA's L4 traffic monitor?

It just tells "all ports" in the settings and reports also only reflect port numbers but no details like

which protocol (tcp/udp).

Anyone?

Best,

Hascha

3 Replies 3

Vance Kwan
Cisco Employee
Cisco Employee

UDP ports will not be blocked.

The L4TM will use the T1 interface to detect traffic to destinations that are on its blacklist.  Once detected, the the data interface on the WSA will send a packet with the TCP reset flag to the client to prevent a TCP connection.

I have not tested this so someone correct me if I am wrong.  I am answering this based on my understanding of the L4TM feature, and how it works.  Since UDP is connectionless, there is no connection for it to kill.

Now this makes me wonder about the Monitor feature though.  But I am almost certain it will not block if the action is set to block.

I'll check this out when I'm in the office and will get back to you.

-Vance

I have confirmed that UDP traffic will not be blocked or monitored by the L4TM feature.  Only TCP.  Hope this helps.

-Vance

Vance Kwan
Cisco Employee
Cisco Employee

I stand corrected now.  The L4TM does indeed block/monitor TCP and UDP (even ICMP).  My previous test/setup were not valid.

-Vance