<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocked Port 25: how to log? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065556#M396072</link>
    <description>&lt;P&gt;Hi all,&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to logging in the IOS.&amp;nbsp; Fairly new to ZFW too, but have set up ZFW to block all internal sytsems from sending through port 25, except the mail server on the LAN.&amp;nbsp; This is to help stop a spambot which I am trying to identify.&amp;nbsp; As typical, antivirus is not helping. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What options should I enable in the IOS (v 15.2) to capture what system(s)is sending on port 25. amd then what commands would I use to monitor the situation?&amp;nbsp; Everything would be at the IOS console.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pleaes and thank you. &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:19:05 GMT</pubDate>
    <dc:creator>cluovpemb</dc:creator>
    <dc:date>2019-03-12T00:19:05Z</dc:date>
    <item>
      <title>Blocked Port 25: how to log?</title>
      <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065556#M396072</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to logging in the IOS.&amp;nbsp; Fairly new to ZFW too, but have set up ZFW to block all internal sytsems from sending through port 25, except the mail server on the LAN.&amp;nbsp; This is to help stop a spambot which I am trying to identify.&amp;nbsp; As typical, antivirus is not helping. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What options should I enable in the IOS (v 15.2) to capture what system(s)is sending on port 25. amd then what commands would I use to monitor the situation?&amp;nbsp; Everything would be at the IOS console.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pleaes and thank you. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065556#M396072</guid>
      <dc:creator>cluovpemb</dc:creator>
      <dc:date>2019-03-12T00:19:05Z</dc:date>
    </item>
    <item>
      <title>Blocked Port 25: how to log?</title>
      <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065557#M396074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect log-drop pkt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That will show you logs with the ip addresses, destination and source ports of connections being dropped by the IOS FW,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2012 17:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065557#M396074</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-05T17:24:33Z</dc:date>
    </item>
    <item>
      <title>Blocked Port 25: how to log?</title>
      <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065558#M396076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi again, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't appear the logging is working or is not configured to show what I need.&amp;nbsp; .&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IfI do &lt;STRONG&gt;sh ip access-lists INSIDE-OUTSIDE&lt;/STRONG&gt;, which is the one I have set with the port 25 blocking, I see in brackets the # of hits the Deny entry has received.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Extended IP access list INSIDE-OUTSIDE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 permit tcp host 192.168.0.123 any eq smtp (74 matches)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 deny tcp any any eq smtp (93 matches)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 permit ip any any (41236 matches)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This 93 goes up somewhat steadily, it was in the 80's this morning.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I do &lt;STRONG&gt;sh policy-map type inspect zone-pair inside-outside sessions &lt;/STRONG&gt;I see some active sessions, no port 25 activity but tha't fine since this show command is for Active sessions, however here's what's at the bottom of the output: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Class-map: class-default (match-any)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Match: any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drop&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 93 packets, 2852 bytes&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;Class-map: class-default (match-any)&lt;BR /&gt;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;So far I can't find any show command that will show me the source of these 93 drops.&amp;nbsp; sh logging | i FW is showing no entries at all, it's almost like logging is broken or something.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2012 19:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065558#M396076</guid>
      <dc:creator>cluovpemb</dc:creator>
      <dc:date>2012-11-06T19:30:37Z</dc:date>
    </item>
    <item>
      <title>Blocked Port 25: how to log?</title>
      <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065559#M396077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It seems that the port 25 hits were just mixed in with a whole bunch of other stuff in the logs.&amp;nbsp; It's a pain to search for since if you do for example sh logging | i :25 yhou get all the timestamps that have that as well.&amp;nbsp; I found a few entries for a PC on the network sending to various IP's over port 25 and have isolated&amp;nbsp; the system.&amp;nbsp; The hit count went up o about 9000 yesterday evening.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just the same, if anybody knows a better technique for handling this type of situation, especially getting better visibility on the offending systems (log filtering?), please advise, thank you.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 14:32:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065559#M396077</guid>
      <dc:creator>cluovpemb</dc:creator>
      <dc:date>2012-11-07T14:32:33Z</dc:date>
    </item>
    <item>
      <title>Blocked Port 25: how to log?</title>
      <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065560#M396078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of device are you using a PIX or ASA...?&amp;nbsp; I'm not fimiliar with what you listed "ZFW"...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 15:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065560#M396078</guid>
      <dc:creator>miguel.desantiago</dc:creator>
      <dc:date>2012-11-07T15:26:36Z</dc:date>
    </item>
    <item>
      <title>Blocked Port 25: how to log?</title>
      <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065561#M396079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Collin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see it with the ip inspect log drop-pkt ( This if the ZBFW is dropping the packets) In case that the ZBFW is not dropping them of course you will not see the logs, I am 100 % sure about this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the logging setup you have on your router to make sure you have it properly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 17:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065561#M396079</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-07T17:30:02Z</dc:date>
    </item>
    <item>
      <title>Blocked Port 25: how to log?</title>
      <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065562#M396080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Miguel, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ZFW is Cisco's official term for zone-baesd firewall, the new IOS Firewall that is.&amp;nbsp; I am just learning it now whilst also trying to implement it on some devices.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It didn't seem to show anything for what I was looking for until I added log to the class-default to make it drop log for the inside-outside pair.&amp;nbsp; Via sh ip access-list INSIDE-OUTSIDE, I was seeing an increasing number of hits against the Deny entry for port 25, and yet sh logging | i FW did not produce any results.&amp;nbsp; But, I've done this and re-done this stuff so many times it's hard to say, so I will just wait and see.&amp;nbsp; I've had ip inspect log DROP_PKT enabled since the beginning.&amp;nbsp; I remove other logging options that are currently enabled and see how that goes.&amp;nbsp; I need to get educated on logging &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 02:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065562#M396080</guid>
      <dc:creator>cluovpemb</dc:creator>
      <dc:date>2012-11-08T02:56:40Z</dc:date>
    </item>
    <item>
      <title>Blocked Port 25: how to log?</title>
      <link>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065563#M396081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to see it is showing stuff now, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure let us know,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 04:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocked-port-25-how-to-log/m-p/2065563#M396081</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-08T04:00:51Z</dc:date>
    </item>
  </channel>
</rss>

