<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcefire Logs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sourcefire-logs/m-p/3308321#M1064691</link>
    <description>&lt;P&gt;Hi sam,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per my understand the new session is the traffic allowed on this session:&lt;/P&gt;
&lt;P&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 match rule order 34, 'companyA-companyB', action Allow&lt;BR /&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 allow action&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same scenario for the traffic allowed on this new session:&lt;/P&gt;
&lt;P&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 match rule order 34, 'companyA-companyB', action Allow&lt;BR /&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 allow action&lt;/P&gt;
&lt;P&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 New session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The delete session mean the traffic expires from the earlier session allowed for the same traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please from the logs verify if the old allowed session also have deleted after some time?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jan 2018 14:22:55 GMT</pubDate>
    <dc:creator>denilson.mota</dc:creator>
    <dc:date>2018-01-09T14:22:55Z</dc:date>
    <item>
      <title>Sourcefire Logs</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-logs/m-p/3307793#M1064689</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can any one please explain me, what does deleting session and new session means in below logs from source fire appliance. Though the rules are allowed on firewall , only one way traffic is seen, I cannot see bi-directional traffic.&amp;nbsp; does it something to do with that deleting session line&amp;nbsp;in bottom of my logs.&lt;BR /&gt;Appreciate any quick response&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 New session&lt;BR /&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 Starting with minimum 0, id 0 and SrcZone first with zones 10 -&amp;gt; 5, geo 0 -&amp;gt; 0, vlan 0, sgt tag: untagged, svc 0, payload 0, client 0, misc 0, user 9999997, icmpType 0, icmpCode 0&lt;BR /&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 match rule order 1, 'Log All Connections', action Audit&lt;BR /&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 match rule order 34, 'companyA-companyB', action Allow&lt;BR /&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 allow action&lt;BR /&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 New session&lt;BR /&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 Starting with minimum 0, id 0 and SrcZone first with zones 10 -&amp;gt; 5, geo 0 -&amp;gt; 0, vlan 0, sgt tag: untagged, svc 0, payload 0, client 0, misc 0, user 9999997, icmpType 0, icmpCode 0&lt;BR /&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 match rule order 1, 'Log All Connections', action Audit&lt;BR /&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 match rule order 34, 'companyA-companyB', action Allow&lt;BR /&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 allow action&lt;BR /&gt;&lt;FONT color="#ff0000"&gt;10.10.10.10-58072 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 Deleting session&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#ff0000"&gt;10.10.10.10-58085 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 Deleting session&lt;/FONT&gt;&lt;BR /&gt;10.10.10.10-50040 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 New session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-logs/m-p/3307793#M1064689</guid>
      <dc:creator>sambillings459</dc:creator>
      <dc:date>2020-02-21T15:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Logs</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-logs/m-p/3308295#M1064690</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can anyone one please help me with above posts.. appreciate any quick response&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 13:49:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-logs/m-p/3308295#M1064690</guid>
      <dc:creator>sambillings459</dc:creator>
      <dc:date>2018-01-09T13:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcefire Logs</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-logs/m-p/3308321#M1064691</link>
      <description>&lt;P&gt;Hi sam,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per my understand the new session is the traffic allowed on this session:&lt;/P&gt;
&lt;P&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 match rule order 34, 'companyA-companyB', action Allow&lt;BR /&gt;10.10.10.10-50019 &amp;gt; 30.30.30.30-4353 6 AS 1 I 7 allow action&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same scenario for the traffic allowed on this new session:&lt;/P&gt;
&lt;P&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 match rule order 34, 'companyA-companyB', action Allow&lt;BR /&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 allow action&lt;/P&gt;
&lt;P&gt;10.10.10.10-60494 &amp;gt; 20.20.20.20-4353 6 AS 1 I 16 New session&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The delete session mean the traffic expires from the earlier session allowed for the same traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please from the logs verify if the old allowed session also have deleted after some time?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 14:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-logs/m-p/3308321#M1064691</guid>
      <dc:creator>denilson.mota</dc:creator>
      <dc:date>2018-01-09T14:22:55Z</dc:date>
    </item>
  </channel>
</rss>

