<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901901#M158167</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Just to understand ,from&amp;nbsp;&lt;SPAN&gt;NAT-config how can we troubleshoot these kind of problems ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2016 11:33:03 GMT</pubDate>
    <dc:creator>bluesea2010</dc:creator>
    <dc:date>2016-03-24T11:33:03Z</dc:date>
    <item>
      <title>syslog message -need help</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901898#M158156</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am getting &amp;nbsp;the below messeges in my syslog&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Built inbound UDP connection x.x.x.x&amp;nbsp;for Outside:public ip /57360 (Public Ip/57360) to Inside:Inside local ip /53 (Inside global IP/53)&lt;/P&gt;
&lt;P&gt;I have not permitted 53 in my access list but it bulit an inbound connection&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901898#M158156</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2019-03-12T07:32:26Z</dc:date>
    </item>
    <item>
      <title>&gt; I have not permitted 53 in</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901899#M158160</link>
      <description>&lt;P&gt;&amp;gt; I have not permitted 53 in my access list but it bulit an inbound connection&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you sure? What is the output of&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;packet-tracer input outside udp 1.2.3.4 1234 INSIDE_GLOBAL_IP 53&lt;/PRE&gt;
&lt;P&gt;Or show your ACL and NAT-config.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 07:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901899#M158160</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-03-24T07:45:33Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901900#M158164</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;our command helped to identify the acl&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 08:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901900#M158164</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2016-03-24T08:49:57Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901901#M158167</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Just to understand ,from&amp;nbsp;&lt;SPAN&gt;NAT-config how can we troubleshoot these kind of problems ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 11:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901901#M158167</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2016-03-24T11:33:03Z</dc:date>
    </item>
    <item>
      <title>&gt; Just to understand ,from</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901902#M158170</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;Just to understand ,from&amp;nbsp;NAT-config how can we troubleshoot these kind of problems ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it just could&amp;nbsp;be used to see if there is any configuration that allows this inbound traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 18:30:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901902#M158170</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-03-24T18:30:29Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901903#M158171</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have done packet tracing &amp;nbsp;, in packet trace &amp;nbsp;acl droped , but in syslog (attached) built connection ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input outside udp globaloutside 53 global inside 58610&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in OUTSIDE-IP 255.255.255.255 identity&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 0.0.0.0 0.0.0.0 via WANinterface-ip, Outside&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: Outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 15:40:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901903#M158171</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2016-03-31T15:40:06Z</dc:date>
    </item>
    <item>
      <title>what are you trying to</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901904#M158172</link>
      <description>&lt;P&gt;what are you trying to simulate with these port-numbers?&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;packet-tracer input outside udp globaloutside 53 global inside 58610&lt;/PRE&gt;
&lt;P&gt;For a real simulation the destination port has to be 53. And which addresses are you using in the trace?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 15:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901904#M158172</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-03-31T15:53:53Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901905#M158173</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am getting dns amplification attack , that's why the source port is 53 (source is address is a public ip from outside and &amp;nbsp;destination is my auto nat ip address which is the outside interface ip of the firewall&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 17:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-message-need-help/m-p/2901905#M158173</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2016-03-31T17:19:25Z</dc:date>
    </item>
  </channel>
</rss>

