<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall Logs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149374#M358081</link>
    <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are logs from the ASA when i open up google.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;192.168.10.3 Apr 15 2013 20:28:55: %ASA-5-304001: 192.168.20.17 Accessed URL 74.125.28.94:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.google.ca/" target="_blank"&gt;http://www.google.ca/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-302013: Built outbound TCP connection 927882 for outside:74.125.28.94/80 (74.125.28.94/80) to Net:192.168.20.17/59525 (217.x.x.x/7436)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-305011: Built dynamic TCP translation from Net:192.168.20.17/59525 to outside:217.x.x.x/7436&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-106100: access-list Net_001 permitted tcp Net/192.168.20.17(59525) -&amp;gt; outside/74.125.28.94(80) hit-cnt 1 first hit [0x3b1e12a4, 0x0]&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-302013: Built outbound TCP connection 927881 for outside:74.125.28.94/80 (74.125.28.94/80) to Net:192.168.20.17/59524 (217.x.x.x/7465)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-305011: Built dynamic TCP translation from Net:192.168.20.17/59524 to outside:217.x.x.x/7465&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-106100: access-list Net_001 permitted tcp Net/192.168.20.17(59524) -&amp;gt; outside/74.125.28.94(80) hit-cnt 1 first hit [0x3b1e12a4, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where 192.168.20.17 is my PC&amp;nbsp; IP.&lt;/P&gt;&lt;P&gt;Net is interface on the ASA &lt;/P&gt;&lt;P&gt;IP 192.168.10.3 also belongs to ASA&amp;nbsp; interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to know whats IP 192.168.10.3 doing here in the ASA logs?&lt;/P&gt;&lt;P&gt;Also is the interface Net&amp;nbsp; is ASA&amp;nbsp; inside interface as it has name of Net and connection goes to outside?&lt;/P&gt;&lt;P&gt;which type of NAT is going on ASA?&lt;/P&gt;&lt;P&gt;Hope make sense &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:29:30 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2019-03-12T01:29:30Z</dc:date>
    <item>
      <title>Firewall Logs</title>
      <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149374#M358081</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are logs from the ASA when i open up google.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;192.168.10.3 Apr 15 2013 20:28:55: %ASA-5-304001: 192.168.20.17 Accessed URL 74.125.28.94:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.google.ca/" target="_blank"&gt;http://www.google.ca/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-302013: Built outbound TCP connection 927882 for outside:74.125.28.94/80 (74.125.28.94/80) to Net:192.168.20.17/59525 (217.x.x.x/7436)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-305011: Built dynamic TCP translation from Net:192.168.20.17/59525 to outside:217.x.x.x/7436&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-106100: access-list Net_001 permitted tcp Net/192.168.20.17(59525) -&amp;gt; outside/74.125.28.94(80) hit-cnt 1 first hit [0x3b1e12a4, 0x0]&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-302013: Built outbound TCP connection 927881 for outside:74.125.28.94/80 (74.125.28.94/80) to Net:192.168.20.17/59524 (217.x.x.x/7465)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-305011: Built dynamic TCP translation from Net:192.168.20.17/59524 to outside:217.x.x.x/7465&lt;BR /&gt;192.168.10.3 Apr 15 2013 20:28:54: %ASA-6-106100: access-list Net_001 permitted tcp Net/192.168.20.17(59524) -&amp;gt; outside/74.125.28.94(80) hit-cnt 1 first hit [0x3b1e12a4, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where 192.168.20.17 is my PC&amp;nbsp; IP.&lt;/P&gt;&lt;P&gt;Net is interface on the ASA &lt;/P&gt;&lt;P&gt;IP 192.168.10.3 also belongs to ASA&amp;nbsp; interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to know whats IP 192.168.10.3 doing here in the ASA logs?&lt;/P&gt;&lt;P&gt;Also is the interface Net&amp;nbsp; is ASA&amp;nbsp; inside interface as it has name of Net and connection goes to outside?&lt;/P&gt;&lt;P&gt;which type of NAT is going on ASA?&lt;/P&gt;&lt;P&gt;Hope make sense &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149374#M358081</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T01:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Logs</title>
      <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149375#M358082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the message "Built outbound" means that the connections is been built from LAN to WAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone was conneting to some Static NAT IP address of server on your ASA then you would be seeing "Built inbound"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The interface IP address 192.168.10.3 in the logs is the IP address of the ASA interface that sends this log to the Syslog server. It doesnt have anything to do with the connection your host is taking to Google.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message "Built Dynamic TCP translation" says that a Dynamic translation is being done through the ASA. Since the port of the NAT IP address doesnt match the real source port I would imagine were talking about Dynamic PAT. So the hosts connections are probably translated to the ASA "outside" interface IP address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 17:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149375#M358082</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-16T17:45:36Z</dc:date>
    </item>
    <item>
      <title>Firewall Logs</title>
      <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149376#M358083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i check config of interface with IP 192.168.10.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it has ip address then it has standby 192.168.10.4&lt;/P&gt;&lt;P&gt;does it refer to standby ASA instead of syslog server?&lt;/P&gt;&lt;P&gt;Also it has ospf cost configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also interface Net does it refer to ASA&amp;nbsp; inside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 18:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149376#M358083</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-16T18:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Logs</title>
      <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149377#M358084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you for example have this kind of interface configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface Ethernet0/1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; description LAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nameif LAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; security-level 100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; ip add 192.168.10.3 255.255.255.0 standby 192.168.10.4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you are probably talking about an ASA failover pair. Two identical ASA firewalls of which only one is Active at a time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA will ALWAYS use the first IP address of 192.168.10.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IP address of 192.168.10.4 is only used to monitor the state of the Failover OR management purposes (and perhaps something else)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The interface named "Net" would in your case seem to refer to an interface that is a LAN interface. Meaning your LAN or part of your LAN is behind it. So I guess you could say its a "inside" interface in that sense though its not named like that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason why you saw the IP address 192.168.10.3 in the Log Messages is that the ASA is using the interface IP address 192.168.10.3 as the source IP address from which it sends the Syslogs to the Syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to change this so that you will actually see the firewall hostname in the Syslog messages you can configure the following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging device-id hostname&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 18:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149377#M358084</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-16T18:18:47Z</dc:date>
    </item>
    <item>
      <title>Firewall Logs</title>
      <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149378#M358085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you keep answering my questions like this then my journey to ASA&amp;nbsp; world will be smooth one.&lt;/P&gt;&lt;P&gt;For you it must be time to sleep now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 20:09:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149378#M358085</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-16T20:09:22Z</dc:date>
    </item>
    <item>
      <title>Firewall Logs</title>
      <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149379#M358086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to be of help &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont spend that many hours sleeping although I probably should &lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/silly.gif"&gt;&lt;/SPAN&gt; I rarely go to sleep before midnight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 20:14:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149379#M358086</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-16T20:14:23Z</dc:date>
    </item>
    <item>
      <title>Firewall Logs</title>
      <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149380#M358087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am surprised still you have lot of energy to answer so many questions in this forum.&lt;/P&gt;&lt;P&gt;To me looks you really love the ASA&amp;nbsp; world.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 20:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149380#M358087</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-16T20:24:29Z</dc:date>
    </item>
    <item>
      <title>Firewall Logs</title>
      <link>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149381#M358088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my work I basically mostly configure ASAs some some aspects of the ASA configurations have become quite familiar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes I test different setups people are asking about here in my home lab also. Maybe learn something new myself in the process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 20:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-logs/m-p/2149381#M358088</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-16T20:30:45Z</dc:date>
    </item>
  </channel>
</rss>

