<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog Anormal amount of Warning message  %ASA-4-106023 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860016#M25966</link>
    <description>&lt;P&gt;This is normal as this is FW, it always block the traffic which was not allowed.&lt;/P&gt;
&lt;P&gt;Only you need to worry about is, is there any traffic from inside originating ?&lt;/P&gt;</description>
    <pubDate>Tue, 21 May 2019 11:06:40 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2019-05-21T11:06:40Z</dc:date>
    <item>
      <title>Syslog Anormal amount of Warning message  %ASA-4-106023</title>
      <link>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860012#M25965</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm getting a very large amount (sometime 10 or 15 per seconds) of&amp;nbsp;&lt;SPAN class="pEM_ErrMsg"&gt;%ASA-4-106023&lt;/SPAN&gt;&amp;nbsp; warnings in the realtime syslog console of a 5506 ASA.&lt;/P&gt;&lt;P&gt;%ASA-4-106023: Deny icmp(or UDP) src Outside:&lt;SPAN&gt;&lt;STRONG&gt;X&lt;/STRONG&gt;&lt;/SPAN&gt; dst Inside: &lt;SPAN&gt;&lt;STRONG&gt;Y&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where sources are always different publics IPs (X) but the destinations are always the same 2 internal IP addresses in my network (which are not leased and have never been leased by the DHCP server nor fixed).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The router CPU is still under 15% but I'm wondering how to prevent these warnings.&lt;/P&gt;&lt;P&gt;I would also like to understand what that really means ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks you for your insights on that matter.&lt;/P&gt;&lt;P&gt;Frederique&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 11:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860012#M25965</guid>
      <dc:creator>FrederiqueCD</dc:creator>
      <dc:date>2019-05-21T11:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Anormal amount of Warning message  %ASA-4-106023</title>
      <link>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860016#M25966</link>
      <description>&lt;P&gt;This is normal as this is FW, it always block the traffic which was not allowed.&lt;/P&gt;
&lt;P&gt;Only you need to worry about is, is there any traffic from inside originating ?&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 11:06:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860016#M25966</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-05-21T11:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Anormal amount of Warning message  %ASA-4-106023</title>
      <link>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860045#M25967</link>
      <description>&lt;P&gt;Hello BB,&lt;/P&gt;&lt;P&gt;Thanks you for your answer. Actually this hosts is alive and is opening session with the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But why is there so many denied udp/icmp packets ? Are they returned packets ? or is it something different ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 11:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860045#M25967</guid>
      <dc:creator>FrederiqueCD</dc:creator>
      <dc:date>2019-05-21T11:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Anormal amount of Warning message  %ASA-4-106023</title>
      <link>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860079#M25968</link>
      <description>&lt;P&gt;FW act based on the Rules you have setup on your network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if this Live Host, i will investigate why this IP sending too many request outside and they are Denied.&lt;/P&gt;
&lt;P&gt;This is unusual single device sending ICMP outside. I will start with Local Device and investigate with remote IP it try to send ICMP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 12:39:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-anormal-amount-of-warning-message-asa-4-106023/m-p/3860079#M25968</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-05-21T12:39:54Z</dc:date>
    </item>
  </channel>
</rss>

