<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reading Logs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reading-logs/m-p/2147688#M361161</link>
    <description>&lt;P&gt;Hello, I'm reading through some logs. The logs contain hits on blacklisted IP address. I'm trying to determine if the connection was stopped at the firewall, but it isn't always clear. I'm trying to determine what is happening when I see the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown UDP connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Built outbound UDP connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown local-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Built local-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might not necessarily help me figure things out, but it seems worth looking into! Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:07:14 GMT</pubDate>
    <dc:creator>Ben F</dc:creator>
    <dc:date>2019-03-12T01:07:14Z</dc:date>
    <item>
      <title>Reading Logs</title>
      <link>https://community.cisco.com/t5/network-security/reading-logs/m-p/2147688#M361161</link>
      <description>&lt;P&gt;Hello, I'm reading through some logs. The logs contain hits on blacklisted IP address. I'm trying to determine if the connection was stopped at the firewall, but it isn't always clear. I'm trying to determine what is happening when I see the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown UDP connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Built outbound UDP connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown local-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Built local-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might not necessarily help me figure things out, but it seems worth looking into! Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reading-logs/m-p/2147688#M361161</guid>
      <dc:creator>Ben F</dc:creator>
      <dc:date>2019-03-12T01:07:14Z</dc:date>
    </item>
    <item>
      <title>Reading Logs</title>
      <link>https://community.cisco.com/t5/network-security/reading-logs/m-p/2147689#M361162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A "Built outbound UDP/TCP connection" message always means that a connection attempt has passed the firewall rules and was allowed to form through the firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A "Teardown UDP/TCP connection" message always means that a connection that was previously allowed to form through the firewall was removed from the firewall for a certain reason. (For TCP connections -&amp;gt; Normal TCP connection close, SYN Timeout, Idle timeout, etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the local-host messages are similiar. I personally look more for the Built/Teardown messages&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall has blocked some connection attempt you would be looking at a log message that starts with "Deny"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think there is a way to show the allowed connections also separately in the log but usually there is no actual need since we see what we need in the "Built" messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 22:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reading-logs/m-p/2147689#M361162</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-27T22:23:15Z</dc:date>
    </item>
  </channel>
</rss>

