<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA Syslog Message 302013 source IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4761905#M1097164</link>
    <description>&lt;P&gt;Thanks, I was also looking for official documentation but can't seem to find any. What ever this is the reason or not, the important thing for me is to understand - will the later IP will always be the source (on outbound), or this may change between different interfaces?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 10:08:49 GMT</pubDate>
    <dc:creator>meirtz4</dc:creator>
    <dc:date>2023-01-25T10:08:49Z</dc:date>
    <item>
      <title>Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4759939#M1097066</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Hi, in the log messages for 302013, on outbound, is it possible to determine the source IP. Meaning who is the IP that initiates the connection? Or is the inbound/outbound indication + IP location in the message only indicating of the security levels?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Some examples:&lt;BR /&gt;Jul 6 09:38:51 44.254.0.8 %ASA-6-302013: Built outbound TCP connection 1465712 for dev:10.2.4.86/25 (10.2.4.86/25) to inside:10.128.85.25/37281 (10.128.85.25/37281)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;%ASA-6-&lt;SPAN class=""&gt;302013&lt;/SPAN&gt;: Built outbound TCP connection 1139888864 for Outside:103.33.237.104/443 (103.33.237.104/443) to Inside:10.12.122.84/17960 (192.44.45.104/17880)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 11:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4759939#M1097066</guid>
      <dc:creator>meirtz4</dc:creator>
      <dc:date>2023-01-23T11:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4759945#M1097067</link>
      <description>&lt;P&gt;You could use a WHOIS (use google to and select a WHOIS site you would like to use) service and lookup the IP address&amp;nbsp;&lt;SPAN&gt;103.33.237.104.&amp;nbsp; Just did a lookup on it and it is an IP located in China.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 12:11:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4759945#M1097067</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-23T12:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4759962#M1097071</link>
      <description>&lt;P&gt;Thank you. Actually what I am trying to achieve, if possible, a definition of which IP will be the source and which is the destination. Meaning, who initiated the connection. From reading the docs, I'm not sure if it's possible. For example in the log with the IP&amp;nbsp;103.33.237.104, is it the IP who initiated the connection? Or the other?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 12:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4759962#M1097071</guid>
      <dc:creator>meirtz4</dc:creator>
      <dc:date>2023-01-23T12:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4759968#M1097072</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116149-qanda-ASA-00.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116149-qanda-ASA-00.pdf&lt;/A&gt;&lt;BR /&gt;answer is here in this link&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 13:02:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4759968#M1097072</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-23T13:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4760005#M1097079</link>
      <description>&lt;P&gt;Usually the&amp;nbsp; log that states "Built" defines the initiating IP.&amp;nbsp; So in your first example, the initiating IP would be 10.2.4.86.&amp;nbsp; But the second example doesn't make sense as it is stating Built outbound TCP connection from the Outside interface.&amp;nbsp; Is this a copy paste error or an actual log message?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Jul 6 09:38:51 44.254.0.8 %ASA-6-302013: Built outbound TCP connection 1465712 for dev:10.2.4.86/25 (10.2.4.86/25) to inside:10.128.85.25/37281 (10.128.85.25/37281)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;%ASA-6-&lt;SPAN class=""&gt;302013&lt;/SPAN&gt;: Built outbound TCP connection 1139888864 for &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Outside&lt;/FONT&gt;&lt;/STRONG&gt;:103.33.237.104/443 (103.33.237.104/443) to Inside:10.12.122.84/17960 (192.44.45.104/17880)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Had the second log message stated Built inbound TCP connection ... for Outside.... then this would mean that the IP 103.33.237.104 is initiating a connection inbound with source port tcp/443.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A better way to validate this is to setup a capture and then go through the captured data in Wireshark&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 13:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4760005#M1097079</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-23T13:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4760028#M1097080</link>
      <description>&lt;P&gt;in addition to what's already been shared, consider the port numbers. TCP connections (and UDP flows) are &lt;STRONG&gt;generally&lt;/STRONG&gt; initiated from an ephemeral port (&amp;gt;1024) to a well-known port. For instance, tcp/25 would be smtp (mail server) and tcp/443 is https (web server). Clients generally initiate connections &lt;STRONG&gt;to&lt;/STRONG&gt; servers.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 14:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4760028#M1097080</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-01-23T14:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4760215#M1097099</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;Thank you for your response.&lt;/P&gt;&lt;P&gt;In the first example, unlike what you assumed, the initiating IP is&amp;nbsp;&lt;SPAN&gt;10.128.85.25. Please refer to this thread -&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-security/asa-syslog-how-is-direction-determined-in-302013-302015/td-p/2008542" target="_blank"&gt;ASA SYSLOG - How is direction determined in 302013 &amp;amp; 302015 - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The second example, which provided by me, is an actual message. I need to decide how to parse it, who is the source and who is the destination. And I agree it doesn't make sense, also I've noticed to the ports as you said.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you think maybe the source and destination IP's has no correlation with outbound/inbound and order?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 19:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4760215#M1097099</guid>
      <dc:creator>meirtz4</dc:creator>
      <dc:date>2023-01-23T19:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4760715#M1097101</link>
      <description>&lt;P&gt;As of yet I have not been able to find any documentation that will support what I am about to write, but this is what I believe why the log message is being displayed in reverse.&lt;/P&gt;
&lt;P&gt;When a connection is established from the inside to the outside on HTTPS that connection the return traffic needs to be allowed and I believe that it is this connection / opening that we see in the log and therefore why it is being showed with IPs in the reverse order.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 09:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4760715#M1097101</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-24T09:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4761905#M1097164</link>
      <description>&lt;P&gt;Thanks, I was also looking for official documentation but can't seem to find any. What ever this is the reason or not, the important thing for me is to understand - will the later IP will always be the source (on outbound), or this may change between different interfaces?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 10:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4761905#M1097164</guid>
      <dc:creator>meirtz4</dc:creator>
      <dc:date>2023-01-25T10:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4761926#M1097165</link>
      <description>&lt;P&gt;The IP itself and the interface associated with the IP will of course change, but the latter will always represent the source.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 10:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4761926#M1097165</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-25T10:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762039#M1097168</link>
      <description>&lt;P&gt;I will check some point with you today.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 12:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762039#M1097168</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-25T12:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762083#M1097176</link>
      <description>&lt;P&gt;Here is a document describing the logs a little more.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116149-qanda-ASA-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116149-qanda-ASA-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 13:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762083#M1097176</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-25T13:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762192#M1097182</link>
      <description>&lt;P&gt;I make small lab, config two ASA FW with allow TCP to OUT of each,&amp;nbsp;&lt;BR /&gt;I run tcp from the R1 toward R2&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I get notification message, it not so helpful but using info in log message&amp;nbsp; and using&amp;nbsp;&lt;BR /&gt;show conn we can get more info. about this traffic,&amp;nbsp;&lt;BR /&gt;TCP have flag we can use it to see if traffic Inbound Outbound direction and also FIN SYN and ACK of traffic.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;in my lab since I tcp from R1 to R2 I can see flag UIO &amp;lt;&amp;lt;- and by using another table I can see that this traffic is&amp;nbsp; Outbound Date, meaning that the traffic initiate from Inside of ASA FW.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (241).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/174382i8B99D64F3F487CB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (241).png" alt="Screenshot (241).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jhkjhkhjkhjklhllh.png" style="width: 945px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/174384i50D1BFD8F40CC6BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="jhkjhkhjkhjklhllh.png" alt="jhkjhkhjkhjklhllh.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 15:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762192#M1097182</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-25T15:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762238#M1097186</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;! Just to be sure:&lt;BR /&gt;inside == R1 == 10.0.0.10 ?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 16:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762238#M1097186</guid>
      <dc:creator>meirtz4</dc:creator>
      <dc:date>2023-01-25T16:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA Syslog Message 302013 source IP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762242#M1097187</link>
      <description>&lt;P&gt;Yes you are correct R1 is 10.0.0.10 and R2 is 20.0.0.20&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 16:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-syslog-message-302013-source-ip/m-p/4762242#M1097187</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-25T16:57:18Z</dc:date>
    </item>
  </channel>
</rss>

