<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error messages on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940699#M436873</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not only that. &lt;/P&gt;&lt;P&gt;There is certain level of "inteligence" built into TD that should catch detect attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But riddle me this, how is TD supposed to differentiate between an actual attack and a misconfigured network device flooding/looping packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A typical scenario I saw causing this, syslog/snmp packets sent through the firewall coincidentally were treated as an attack because of the amount of packets in short bursts. In this case the root cause turned out ot be ops personel setting logging level to high for some unrelated troubleshooting session and not setting it back. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 May 2012 17:35:54 GMT</pubDate>
    <dc:creator>Marcin Latosiewicz</dc:creator>
    <dc:date>2012-05-15T17:35:54Z</dc:date>
    <item>
      <title>Error messages on ASA</title>
      <link>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940694#M436860</link>
      <description>&lt;P&gt;I see following message very frequent on ASA ASDM Syslog messages window; what could be possible reason of these messages and what is the remedy to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[ Scanning] drop rate-1 exceeded. Current burst rate is 42 per second, max configured rate is 10; Current average rate is 60 per second, max configured rate is 5; Cumulative total count is 36350&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940694#M436860</guid>
      <dc:creator>rehan_uet</dc:creator>
      <dc:date>2019-03-11T23:07:29Z</dc:date>
    </item>
    <item>
      <title>Error messages on ASA</title>
      <link>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940695#M436862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;those are produced by threat detection features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;show run all threat-detection&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;will all you to see all settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 17:17:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940695#M436862</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-05-15T17:17:26Z</dc:date>
    </item>
    <item>
      <title>Error messages on ASA</title>
      <link>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940696#M436863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Should I ignore these messages?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 17:18:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940696#M436863</guid>
      <dc:creator>rehan_uet</dc:creator>
      <dc:date>2012-05-15T17:18:55Z</dc:date>
    </item>
    <item>
      <title>Error messages on ASA</title>
      <link>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940697#M436865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's up to you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The defaults are pretty OK, but it's hard to configure something that would be optimal for everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More info:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/system/message/logmsgs.html#wp4963969"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/system/message/logmsgs.html#wp4963969&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 17:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940697#M436865</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-05-15T17:25:53Z</dc:date>
    </item>
    <item>
      <title>Error messages on ASA</title>
      <link>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940698#M436872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; My understanding is there is no harm of these messages and these messages just give the alert about attack; am I correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 17:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940698#M436872</guid>
      <dc:creator>rehan_uet</dc:creator>
      <dc:date>2012-05-15T17:28:38Z</dc:date>
    </item>
    <item>
      <title>Error messages on ASA</title>
      <link>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940699#M436873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not only that. &lt;/P&gt;&lt;P&gt;There is certain level of "inteligence" built into TD that should catch detect attack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But riddle me this, how is TD supposed to differentiate between an actual attack and a misconfigured network device flooding/looping packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A typical scenario I saw causing this, syslog/snmp packets sent through the firewall coincidentally were treated as an attack because of the amount of packets in short bursts. In this case the root cause turned out ot be ops personel setting logging level to high for some unrelated troubleshooting session and not setting it back. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 17:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-messages-on-asa/m-p/1940699#M436873</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-05-15T17:35:54Z</dc:date>
    </item>
  </channel>
</rss>

