<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ip audit - ASA 7.2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954947#M402040</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been reading &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1718159" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1718159&lt;/A&gt; but I'm still a little bit confused about ip audit on Cisco ASA. I'm not sure traffic is denied based on my ip audit configuration as regard signature 6053. I have the following configuration, as it is in the example ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit name insidepolicy1 attack action alarm&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit name insidepolicy2 info action alarm&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit name outsidepolicy1 attack action reset&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit name outsidepolicy2 info action alarm&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit interface inside insidepolicy1&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit interface inside insidepolicy2&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit interface outside outsidepolicy1&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit interface outside outsidepolicy2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.. but I do not have any action defined with ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit info (or) attack action ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got many warnings regarding signature 6053 and it seems to be traffic is denied cause I have a reset action applied on &lt;/P&gt;&lt;P&gt;outsidepolicy1. Can someone confirrm it is correct? Mostly is confusing because document above says that in ASA 7.2 6053 is A(attack) but checking the firewall ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname# sh ip audit count interface outside&lt;/P&gt;&lt;P&gt;IP AUDIT INTERFACE COUNTERS: outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6053 I DNS All Records&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55402&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.. 6053 is I(info)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:31:23 GMT</pubDate>
    <dc:creator>giuseppe parlato</dc:creator>
    <dc:date>2019-03-11T23:31:23Z</dc:date>
    <item>
      <title>ip audit - ASA 7.2</title>
      <link>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954947#M402040</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been reading &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1718159" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1718159&lt;/A&gt; but I'm still a little bit confused about ip audit on Cisco ASA. I'm not sure traffic is denied based on my ip audit configuration as regard signature 6053. I have the following configuration, as it is in the example ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit name insidepolicy1 attack action alarm&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit name insidepolicy2 info action alarm&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit name outsidepolicy1 attack action reset&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit name outsidepolicy2 info action alarm&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit interface inside insidepolicy1&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit interface inside insidepolicy2&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit interface outside outsidepolicy1&lt;/P&gt;&lt;P&gt;hostname(config)# ip audit interface outside outsidepolicy2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.. but I do not have any action defined with ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit info (or) attack action ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got many warnings regarding signature 6053 and it seems to be traffic is denied cause I have a reset action applied on &lt;/P&gt;&lt;P&gt;outsidepolicy1. Can someone confirrm it is correct? Mostly is confusing because document above says that in ASA 7.2 6053 is A(attack) but checking the firewall ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname# sh ip audit count interface outside&lt;/P&gt;&lt;P&gt;IP AUDIT INTERFACE COUNTERS: outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6053 I DNS All Records&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55402&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.. 6053 is I(info)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954947#M402040</guid>
      <dc:creator>giuseppe parlato</dc:creator>
      <dc:date>2019-03-11T23:31:23Z</dc:date>
    </item>
    <item>
      <title>ip audit - ASA 7.2</title>
      <link>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954948#M402041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;You've defined your basic IPS features in your Cisco ASA FW correctly. The actions are alarm, reset and drop. In your case, you've defined insidepolicy1 attack action alarm &amp;amp; outsidepolicy1 attack action reset. Alarm here means the Cisco ASA FW will generate a syslog message stating that a packet matched a signature (total is 59 signatures only).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides the above mentioned configuration, you may want to disable some of the default Cisco ASA FW signatures to reduce high FALSE POSITIVE alarms as shown below;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;! Timestamp considered DOS but needed for RFC1323 support&lt;BR /&gt;ip audit signature 1002 disable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! ICMP echo reply&lt;BR /&gt;ip audit signature 2000 disable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! ICMP unreachable&lt;BR /&gt;ip audit signature 2001 disable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! ICMP echo request&lt;BR /&gt;ip audit signature 2004 disable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! ICMP time exceeded&lt;BR /&gt;ip audit signature 2005 disable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! DNS zone transfer - we are likely doing these and do not want to drop&lt;BR /&gt;ip audit signature 6051 disable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! DNS All Records - we are likely doing these and do not want to drop&lt;/P&gt;&lt;P&gt;ip audit signature 6053 disable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 18:22:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954948#M402041</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-17T18:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: ip audit - ASA 7.2</title>
      <link>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954949#M402042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer, actually I'm not sure traffic matching outsidepolicy1 is going to really drop and reset connection, surely&lt;/P&gt;&lt;P&gt;outsidepolicy2 is sending a warning log (%ASA-4-400037: IDS:6053 DNS all records request from **) but I do not have a reset or something else log message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS All Records signature through ASDM is (A) so why a &lt;SPAN style="color: #0000ff;"&gt;show ip audit count interface outside&lt;/SPAN&gt; command gives me the following output ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6053 &lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;I&lt;/STRONG&gt;&lt;/SPAN&gt; DNS All Records&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55402&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should'nt it be ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6053 &lt;SPAN&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;&lt;/SPAN&gt; DNS All Records&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55402&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ps. I cannot disable DNS All Records signature&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 22:46:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954949#M402042</guid>
      <dc:creator>giuseppe parlato</dc:creator>
      <dc:date>2012-07-17T22:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: ip audit - ASA 7.2</title>
      <link>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954950#M402043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Yes, the outsidepolicy2 behavior is correct. It sends you log messages because the action has been set to alarm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You’re correct, in my lab Cisco ASA FW v8.0.2, the 6053 DNS All Records signature should be A, I’m surprised you’re seeing it as I. Can you paste here your "show ip audit count" output?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, when you disable a signature in your Cisco ASA FW IP AUDIT, what it means is, you’re not inspecting the packets that matches the signature. It was pass through, permitted. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 03:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-audit-asa-7-2/m-p/1954950#M402043</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-18T03:25:53Z</dc:date>
    </item>
  </channel>
</rss>

