<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Inconsistent ACL hits seen in syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3710456#M12193</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea why traffic destined to port 443 might be&amp;nbsp;bypassing an ACL for that port and hitting an &lt;EM&gt;IP any/any&lt;/EM&gt; ACL that's at the bottom of the list, at least according to syslog.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ACLs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;access-list inside_access_in line 5 extended permit tcp 10.1.0.0 255.255.0.0 any4 object-group DM_INLINE_TCP_6 (https &amp;amp; https) log disable (hitcnt=2951027) 0xb0c12c26


access-list inside_access_in line 24 extended permit ip any4 any4 log informational interval 300 (hitcnt=295888) 0x2bc0c8ca&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;What i see in syslog:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;12-09-2018 15:22:19 Local7.Info 10.1.1.232 %ASA-6-106100: access-list inside_access_in permitted tcp inside/10.1.2.91(52106) -&amp;gt; outside-WAN/52.114.76.35(443) hit-cnt 1 first hit [0xb0c12c26, 0x15b7e092]


12-09-2018 15:22:19 Local7.Info 10.1.1.232 %ASA-6-106100: access-list inside_access_in permitted udp inside/10.1.2.7(51150) -&amp;gt; outside-WAN/216.58.206.46(443) hit-cnt 1 first hit [0x2bc0c8ca, 0x00000000]&lt;/PRE&gt;
&lt;P&gt;How&amp;nbsp;reliable is the information coming from syslog?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:15:49 GMT</pubDate>
    <dc:creator>Nasos Ergot</dc:creator>
    <dc:date>2020-02-21T16:15:49Z</dc:date>
    <item>
      <title>Inconsistent ACL hits seen in syslog</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3710456#M12193</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea why traffic destined to port 443 might be&amp;nbsp;bypassing an ACL for that port and hitting an &lt;EM&gt;IP any/any&lt;/EM&gt; ACL that's at the bottom of the list, at least according to syslog.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ACLs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;access-list inside_access_in line 5 extended permit tcp 10.1.0.0 255.255.0.0 any4 object-group DM_INLINE_TCP_6 (https &amp;amp; https) log disable (hitcnt=2951027) 0xb0c12c26


access-list inside_access_in line 24 extended permit ip any4 any4 log informational interval 300 (hitcnt=295888) 0x2bc0c8ca&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;What i see in syslog:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;12-09-2018 15:22:19 Local7.Info 10.1.1.232 %ASA-6-106100: access-list inside_access_in permitted tcp inside/10.1.2.91(52106) -&amp;gt; outside-WAN/52.114.76.35(443) hit-cnt 1 first hit [0xb0c12c26, 0x15b7e092]


12-09-2018 15:22:19 Local7.Info 10.1.1.232 %ASA-6-106100: access-list inside_access_in permitted udp inside/10.1.2.7(51150) -&amp;gt; outside-WAN/216.58.206.46(443) hit-cnt 1 first hit [0x2bc0c8ca, 0x00000000]&lt;/PRE&gt;
&lt;P&gt;How&amp;nbsp;reliable is the information coming from syslog?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3710456#M12193</guid>
      <dc:creator>Nasos Ergot</dc:creator>
      <dc:date>2020-02-21T16:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent ACL hits seen in syslog</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3710582#M12195</link>
      <description>&lt;P&gt;The second log showed udp.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;12-09-2018 15:22:19 Local7.Info 10.1.1.232 %ASA-6-106100: access-list inside_access_in permitted udp inside/10.1.2.7(51150) -&amp;gt; outside-WAN/216.58.206.46(443) hit-cnt 1 first hit [0x2bc0c8ca, 0x00000000]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 16:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3710582#M12195</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2018-09-20T16:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent ACL hits seen in syslog</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3711114#M12280</link>
      <description>&lt;P&gt;You are absolutely right.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 13:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3711114#M12280</guid>
      <dc:creator>Kykeonas</dc:creator>
      <dc:date>2018-09-21T13:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent ACL hits seen in syslog</title>
      <link>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3711118#M12282</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need glasses.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 13:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inconsistent-acl-hits-seen-in-syslog/m-p/3711118#M12282</guid>
      <dc:creator>Nasos Ergot</dc:creator>
      <dc:date>2018-09-21T13:18:52Z</dc:date>
    </item>
  </channel>
</rss>

