<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 5525-x, 8.6 drop log entries? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196377#M361807</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does not make any sense as everything is working fine...One question..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the ASA the only available way out on your network. I mean the internal users and DMZ can only go out via the ASA, there is no other gateway or rogue device providing internet to the outside, so we could be seeing asymetric routing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Feb 2013 04:29:26 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-02-22T04:29:26Z</dc:date>
    <item>
      <title>5525-x, 8.6 drop log entries?</title>
      <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196376#M361806</link>
      <description>&lt;P&gt;I just deployed a 5525-x.&amp;nbsp; I am doing dynamic PAT from the inside to the outside interface.&amp;nbsp; I noticed I am having a lot of these activities logged in my syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in denied tcp outside/184.168.232.7(80) -&amp;gt; inside/172.29.6.50(52055) hit-cnt 1 first hit [0x2c1c6a65, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in denied udp outside/8.8.8.8(53) -&amp;gt; DMZOUTSIDE/192.168.1.100(63313) hit-cnt 1 first hit [0x2c1c6a65, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(syslog id - 106100)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What this appears to be is return traffic to my inside hosts.&amp;nbsp; What is strange though is everything appears to be working correctly.&amp;nbsp; Any ideas as to why the ASA drops/logs this info?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196376#M361806</guid>
      <dc:creator>Dave Phillips</dc:creator>
      <dc:date>2019-03-12T01:02:17Z</dc:date>
    </item>
    <item>
      <title>5525-x, 8.6 drop log entries?</title>
      <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196377#M361807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does not make any sense as everything is working fine...One question..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the ASA the only available way out on your network. I mean the internal users and DMZ can only go out via the ASA, there is no other gateway or rogue device providing internet to the outside, so we could be seeing asymetric routing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 04:29:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196377#M361807</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-02-22T04:29:26Z</dc:date>
    </item>
    <item>
      <title>5525-x, 8.6 drop log entries?</title>
      <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196378#M361808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the late reply.&amp;nbsp; I wanted to rule out asymetric routing as I was in the process of migrating users over to the ASA.&amp;nbsp; That has been ruled out, only one way in and out and that is through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still seeing the drops logged.&amp;nbsp; I am using Manual NAT (after auto) to the outside interface to dynamically pat.&amp;nbsp; I have added an explicit deny all to the end of my outside_in access list, which is what is catching all these entries.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 14:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196378#M361808</guid>
      <dc:creator>Dave Phillips</dc:creator>
      <dc:date>2013-03-06T14:59:44Z</dc:date>
    </item>
    <item>
      <title>5525-x, 8.6 drop log entries?</title>
      <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196379#M361810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And everything is working perfect right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hmm Are you still getting the logs for that particular 8.8.8.8, if yes please proceed with a capture on the outside interface to see what is going on &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 17:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196379#M361810</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-06T17:03:41Z</dc:date>
    </item>
    <item>
      <title>5525-x, 8.6 drop log entries?</title>
      <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196380#M361812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ouch.....after evaluating LOTS of traffic, I think I have seen some patterns.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 8.8.8.8 log entry seems to come after the DNS server sends a "server fault" reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other entries all seem to come from late traffic?&amp;nbsp; I will see a http [RST, ACK] sent from the inside host to the web server, then right after that I will see several packets arrive (wireshark labels them as - TCP segment of a reassembled PDU).&amp;nbsp; ASA drops the packets and throws the log entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds like the ASA is doing what it should be doing, but since I am logging 3-4,000 of these an hour......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UPDATE:&lt;/P&gt;&lt;P&gt;I just added a deny ip any any to the end of a different ASA (my home) and I seem to noticing the same amount of log activity.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 22:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196380#M361812</guid>
      <dc:creator>Dave Phillips</dc:creator>
      <dc:date>2013-03-12T22:06:43Z</dc:date>
    </item>
    <item>
      <title>5525-x, 8.6 drop log entries?</title>
      <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196381#M361813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An ASA on your place NICE &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;.... I want to get one as well....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the same kind of drops the ones you are seeing on your ASA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean with the deny ip any any at the end you are gonna get way to much information. that depending on what kind of traffic is expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you create the following:&lt;/P&gt;&lt;P&gt;cap asp type asp-drop all circular-buffer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then let it go over a few seconds and share the following:&lt;/P&gt;&lt;P&gt;show cap asp | include x.x.x.x ( Where this is the IP address of the traffic being dropped that you are troubleshooting)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 22:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196381#M361813</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-12T22:52:01Z</dc:date>
    </item>
    <item>
      <title>5525-x, 8.6 drop log entries?</title>
      <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196382#M361814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not really getting much new info from the ASP capture, but &lt;SPAN style="font-size: 10pt;"&gt;I am beginning to think the drops I am seeing here is perfectly normal.&amp;nbsp; It just caught me by surprise. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is been a great learning experience and I appreciate your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 16:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196382#M361814</guid>
      <dc:creator>Dave Phillips</dc:creator>
      <dc:date>2013-03-13T16:32:54Z</dc:date>
    </item>
    <item>
      <title>5525-x, 8.6 drop log entries?</title>
      <link>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196383#M361815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah that's what I would think,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear that I could help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 16:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5525-x-8-6-drop-log-entries/m-p/2196383#M361815</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-13T16:47:55Z</dc:date>
    </item>
  </channel>
</rss>

