<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISCO ASA icmp logs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451507#M1083054</link>
    <description>&lt;P&gt;Can you post sample Log here to understand the issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Aug 2021 22:28:57 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-08-18T22:28:57Z</dc:date>
    <item>
      <title>CISCO ASA icmp logs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451502#M1083053</link>
      <description>&lt;P&gt;The ICMP logs (ASA-6-302021) we are currently receiving from the ASA do not contain the byte count for the packet. Is this design intent or a config issue?&lt;/P&gt;&lt;P&gt;With the rise in hackers using icmp for exfil this is a critical piece of data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ihor&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 22:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451502#M1083053</guid>
      <dc:creator>ihor.nakonecznyj</dc:creator>
      <dc:date>2021-08-18T22:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA icmp logs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451507#M1083054</link>
      <description>&lt;P&gt;Can you post sample Log here to understand the issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 22:28:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451507#M1083054</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-18T22:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA icmp logs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451508#M1083055</link>
      <description>9:07:23.000 PM&lt;BR /&gt;Aug 18 16:07:23 10.a.a.a %ASA-6-302021: Teardown ICMP connection for faddr 10.b.b.b/45883 gaddr 10.c.c.c/0 laddr 10.c.c.c/0 type 8 code 0&lt;BR /&gt;BTW, what is faddr gaddr and laddr?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 18 Aug 2021 22:33:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451508#M1083055</guid>
      <dc:creator>ihor.nakonecznyj</dc:creator>
      <dc:date>2021-08-18T22:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA icmp logs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451518#M1083056</link>
      <description>&lt;H3 id="ariaid-title15" class="title topictitle3"&gt;02021&lt;/H3&gt;
&lt;SECTION class="body conbody"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Error Message&lt;/STRONG&gt;&lt;CODE class="ph codeph"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;%&lt;SPAN class="ph"&gt;ASA&lt;/SPAN&gt;-6-302021: Teardown ICMP connection for faddr {&lt;EM class="ph i"&gt;faddr&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="ph i"&gt;icmp_seq_num&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;} [(&lt;EM class="ph i"&gt;idfw_user&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;)] gaddr {&lt;EM class="ph i"&gt;gaddr&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="ph i"&gt;icmp_type&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;} laddr&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="ph i"&gt;laddr&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;[(&lt;EM class="ph i"&gt;idfw_user&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;)] type {&lt;EM class="ph i"&gt;type&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;} code {&lt;EM class="ph i"&gt;code&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;}&lt;/CODE&gt;&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Explanation&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;An ICMP session is removed in the fast-path when stateful ICMP is enabled using the inspect icmp command. The following list describes the message values:&lt;/P&gt;
&lt;UL id="con_8399919__ul_4594167191724995B79214303A690EAD" class="ul"&gt;
&lt;LI id="con_8399919__li_5828BE6D42F746488B875A2805406252" class="li"&gt;&lt;EM class="ph i"&gt;faddr&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;—Specifies the IP address of the foreign host&lt;/LI&gt;
&lt;LI id="con_8399919__li_B86DF0DD57BF41FC92A95C061EAC0454" class="li"&gt;&lt;EM class="ph i"&gt;gaddr&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;—Specifies the IP address of the global host&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;EM class="ph i"&gt;laddr&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;—Specifies the IP address of the local host&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;EM class="ph i"&gt;idfw_user&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;—The name of the identity firewall user&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;EM class="ph i"&gt;user&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;—The username associated with the host from where the connection was initiated&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;EM class="ph i"&gt;type&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;—Specifies the ICMP type&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;EM class="ph i"&gt;code&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;—Specifies the ICMP code&lt;/LI&gt;
&lt;/UL&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Wed, 18 Aug 2021 22:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451518#M1083056</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-18T22:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO ASA icmp logs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451519#M1083057</link>
      <description>Thank you. So, no byte count for the packet? Is there a different ASA icmp log that would contain the packet byte count?&lt;BR /&gt;&lt;BR /&gt;TIA&lt;BR /&gt;&lt;BR /&gt;Ihor&lt;BR /&gt;</description>
      <pubDate>Wed, 18 Aug 2021 23:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-icmp-logs/m-p/4451519#M1083057</guid>
      <dc:creator>ihor.nakonecznyj</dc:creator>
      <dc:date>2021-08-18T23:03:11Z</dc:date>
    </item>
  </channel>
</rss>

