Show localhost Command

Connection

192.168.10.11

Connection

192.168.10.11

fw1# show local-host

Interface dmz: 0 active, 0 maximum active, 0 denied Interface inside: 1 active, 5 maximum active, 0 denied local host: < 10.0.0.11 >,

TCP flow count/limit = 2/300 TCP embryonic count to host = 0 TCP intercept watermark = 25 UDP flow count/limit = 0/unlimited

TCP out 192.168.10.11 :80 in 10.0.0.11 :2824 idle 0:00:05 bytes 466 flags UIO TCP out 192.168.10.11 :80 in 10.0.0.11 :2823 idle 0:00:05 bytes 1402 flags UIO

Interface outside: 1 active, 1 maximum active, 0 denied local host: < 192.168.10.11 >,

TCP flow count/limit = 2/unlimited TCP embryonic count to host = 0 TCP intercept watermark = unlimited UDP flow count/limit = 0/unlimited

The show local-host command enables you to display the network states of local hosts. A local host is created for any host that forwards traffic to or through the security appliance. This command lets you show the translation and connection slots for the local hosts. In the figure, the inside host 10.0.0.11 establishes two web connections with server 192.168.10.11. The output of show local-host is displayed.

This command also displays the connection limit values. In the figure, the current TCP flow count for local host 10.0.0.11is 2 with a limit of 300. If a connection limit is not set, the value displays as "unlimited." In the event of a SYN attack (with TCP Intercept configured), the show local-host command output includes the TCP embryonic count to host and the TCP Intercept watermark. In the figure, the embryonic threshold is set for local host 10.0.0.11 at 25 and the current number of embryonic connections is 0.

You can use the command clear local-host [ip_address], to clear the network state of all local hosts or of a specific IP address. It stops all connections and translations that are associated with the local hosts or with the specific IP address specified in the command.

The syntax for the local-host command is as follows:

Conn:

TCP out 192.168.10.11 :80 in insidehost:2824 idle 0:00:05 bytes 466 flags UIO TCP out 192.168.10.11 :80 in insidehost:2823 idle 0:00:05 bytes 1402 flags UIO

© 2005 Cisco Systems, Inc. All rights

clear local-host [ip address] show local-host [ip address]

local-host Command ip_address

(Optional) Local host IP address.

Translation

Translation

pixfirewall#

show xlate

pixfirewall#

show xlate

Continue reading here: Show xlate detail Command

Was this article helpful?

0 0