<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SNMP - False positive in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snmp-false-positive/m-p/2085244#M394192</link>
    <description>&lt;P&gt;HI all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently facing with an issue which relate to a false positive.&lt;/P&gt;&lt;P&gt;if someone could help me out here I would greatly appreciate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;base on the above, we have configure to collect SNMP traps, We have set the connection limit to 50000 but we had an issue few weeks ago (and we got the right error message: “Connection limit exceeded 50000/50000”). To solve the issue we have set it to 0 (unlimited) but we still have the syslog message.&lt;/P&gt;&lt;P&gt;the log message is&lt;/P&gt;&lt;P&gt;Connection Limit exceeded 81532/0 for input packet from x.x.x.x/443 to y.y.y.y/1376 on interface ABC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we want to set up a SNMP trap for that message but it’s a false positive now…&lt;/P&gt;&lt;P&gt;any idea how to get ride of this please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with kind regards,&lt;/P&gt;&lt;P&gt;Lancellot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt;&lt;P class="MsoNormal" style="margin-left: 35.4pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;/DIV&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:36:29 GMT</pubDate>
    <dc:creator>Lance Wendel</dc:creator>
    <dc:date>2019-03-12T00:36:29Z</dc:date>
    <item>
      <title>SNMP - False positive</title>
      <link>https://community.cisco.com/t5/network-security/snmp-false-positive/m-p/2085244#M394192</link>
      <description>&lt;P&gt;HI all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently facing with an issue which relate to a false positive.&lt;/P&gt;&lt;P&gt;if someone could help me out here I would greatly appreciate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;base on the above, we have configure to collect SNMP traps, We have set the connection limit to 50000 but we had an issue few weeks ago (and we got the right error message: “Connection limit exceeded 50000/50000”). To solve the issue we have set it to 0 (unlimited) but we still have the syslog message.&lt;/P&gt;&lt;P&gt;the log message is&lt;/P&gt;&lt;P&gt;Connection Limit exceeded 81532/0 for input packet from x.x.x.x/443 to y.y.y.y/1376 on interface ABC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we want to set up a SNMP trap for that message but it’s a false positive now…&lt;/P&gt;&lt;P&gt;any idea how to get ride of this please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with kind regards,&lt;/P&gt;&lt;P&gt;Lancellot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt;&lt;P class="MsoNormal" style="margin-left: 35.4pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:36:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-false-positive/m-p/2085244#M394192</guid>
      <dc:creator>Lance Wendel</dc:creator>
      <dc:date>2019-03-12T00:36:29Z</dc:date>
    </item>
  </channel>
</rss>

