<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Deny UDP reverse path check in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deny-udp-reverse-path-check/m-p/1810151#M456565</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All syslogs ASA 8.3 are referenced here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can easily google for different version of this document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as checking what that IP is. Best start by checking whois &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case it's verisign ... not sure why anyone would send UDP to it ... you might need to sniff traffic.&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;whois 198.41.0.4&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;# Query terms are ambiguous.&amp;nbsp; The query is assumed to be:&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "n 198.41.0.4"&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;# Use "?" to get help.&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;# The following results may also be obtained via:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/nets;q=198.41.0.4?showDetails=true&amp;amp;showARIN=false&amp;amp;ext=netref2"&gt;http://whois.arin.net/rest/nets;q=198.41.0.4?showDetails=true&amp;amp;showARIN=false&amp;amp;ext=netref2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NetRange:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.41.0.0 - 198.41.3.255&lt;/P&gt;&lt;P&gt;CIDR:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.41.0.0/22&lt;/P&gt;&lt;P&gt;OriginAS:&lt;/P&gt;&lt;P&gt;NetName:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INTERNIC1&lt;/P&gt;&lt;P&gt;NetHandle:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NET-198-41-0-0-1&lt;/P&gt;&lt;P&gt;Parent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NET-198-0-0-0-0&lt;/P&gt;&lt;P&gt;NetType:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Direct Assignment&lt;/P&gt;&lt;P&gt;RegDate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1993-01-04&lt;/P&gt;&lt;P&gt;Updated:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2005-01-13&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ref:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/net/NET-198-41-0-0-1"&gt;http://whois.arin.net/rest/net/NET-198-41-0-0-1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OrgName:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VeriSign Infrastructure &amp;amp; Operations&lt;/P&gt;&lt;P&gt;OrgId:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIO-2&lt;/P&gt;&lt;P&gt;Address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12061 Bluemont Way&lt;/P&gt;&lt;P&gt;City:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reston&lt;/P&gt;&lt;P&gt;StateProv:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VA&lt;/P&gt;&lt;P&gt;PostalCode:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20190&lt;/P&gt;&lt;P&gt;Country:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; US&lt;/P&gt;&lt;P&gt;RegDate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2002-07-11&lt;/P&gt;&lt;P&gt;Updated:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-01-03&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ref:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/org/VIO-2"&gt;http://whois.arin.net/rest/org/VIO-2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OrgAbuseHandle: NETWO480-ARIN&lt;/P&gt;&lt;P&gt;OrgAbuseName:&amp;nbsp;&amp;nbsp; Network Admin&lt;/P&gt;&lt;P&gt;OrgAbusePhone:&amp;nbsp; +1-703-948-4300&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OrgAbuseEmail:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:netadmin@verisign.com"&gt;netadmin@verisign.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OrgAbuseRef:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/poc/NETWO480-ARIN"&gt;http://whois.arin.net/rest/poc/NETWO480-ARIN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OrgTechHandle: NETWO480-ARIN&lt;/P&gt;&lt;P&gt;OrgTechName:&amp;nbsp;&amp;nbsp; Network Admin&lt;/P&gt;&lt;P&gt;OrgTechPhone:&amp;nbsp; +1-703-948-4300&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OrgTechEmail:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:netadmin@verisign.com"&gt;netadmin@verisign.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OrgTechRef:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/poc/NETWO480-ARIN"&gt;http://whois.arin.net/rest/poc/NETWO480-ARIN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;# ARIN WHOIS data and services are subject to the Terms of Use&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# available at: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.arin.net/whois_tou.html"&gt;https://www.arin.net/whois_tou.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jan 2012 14:52:20 GMT</pubDate>
    <dc:creator>Marcin Latosiewicz</dc:creator>
    <dc:date>2012-01-18T14:52:20Z</dc:date>
    <item>
      <title>Deny UDP reverse path check</title>
      <link>https://community.cisco.com/t5/network-security/deny-udp-reverse-path-check/m-p/1810150#M456564</link>
      <description>&lt;P&gt;We have a ASA up for a few years now and I am finally trying to understand some of the syslog info.&amp;nbsp; I configured it yesterday to email any Alerts and Emergency messages.&amp;nbsp; In the past 21 hrs I have received 511 (I'm glad I had conversation view enabled in Outlook).&amp;nbsp; I have many questions but I will start with why, throughout the night, I receive (over 100) something like this:&lt;/P&gt;&lt;P&gt;&amp;lt;185&amp;gt;Jan 18 2012 07:23:32: %ASA-1-106021: Deny UDP reverse path check from 169.254.146.189 to 198.41.0.4 on interface inside&lt;/P&gt;&lt;P&gt;Looks like a Windows client with a self assigned IP. We have an open wireless "guest" network for students to use for the smart phones, etc..., which is always out of IP addresses.&amp;nbsp;&amp;nbsp;&amp;nbsp; What is it trying to do? What is 198.41.0.4 (always different)?&amp;nbsp; If these are harmless, can I stop it from reporting them?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-udp-reverse-path-check/m-p/1810150#M456564</guid>
      <dc:creator>mbasso1676</dc:creator>
      <dc:date>2019-03-11T22:15:58Z</dc:date>
    </item>
    <item>
      <title>Deny UDP reverse path check</title>
      <link>https://community.cisco.com/t5/network-security/deny-udp-reverse-path-check/m-p/1810151#M456565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All syslogs ASA 8.3 are referenced here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can easily google for different version of this document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as checking what that IP is. Best start by checking whois &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case it's verisign ... not sure why anyone would send UDP to it ... you might need to sniff traffic.&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;whois 198.41.0.4&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;# Query terms are ambiguous.&amp;nbsp; The query is assumed to be:&lt;/P&gt;&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "n 198.41.0.4"&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;# Use "?" to get help.&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;# The following results may also be obtained via:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/nets;q=198.41.0.4?showDetails=true&amp;amp;showARIN=false&amp;amp;ext=netref2"&gt;http://whois.arin.net/rest/nets;q=198.41.0.4?showDetails=true&amp;amp;showARIN=false&amp;amp;ext=netref2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NetRange:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.41.0.0 - 198.41.3.255&lt;/P&gt;&lt;P&gt;CIDR:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.41.0.0/22&lt;/P&gt;&lt;P&gt;OriginAS:&lt;/P&gt;&lt;P&gt;NetName:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INTERNIC1&lt;/P&gt;&lt;P&gt;NetHandle:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NET-198-41-0-0-1&lt;/P&gt;&lt;P&gt;Parent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NET-198-0-0-0-0&lt;/P&gt;&lt;P&gt;NetType:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Direct Assignment&lt;/P&gt;&lt;P&gt;RegDate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1993-01-04&lt;/P&gt;&lt;P&gt;Updated:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2005-01-13&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ref:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/net/NET-198-41-0-0-1"&gt;http://whois.arin.net/rest/net/NET-198-41-0-0-1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OrgName:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VeriSign Infrastructure &amp;amp; Operations&lt;/P&gt;&lt;P&gt;OrgId:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIO-2&lt;/P&gt;&lt;P&gt;Address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12061 Bluemont Way&lt;/P&gt;&lt;P&gt;City:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reston&lt;/P&gt;&lt;P&gt;StateProv:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VA&lt;/P&gt;&lt;P&gt;PostalCode:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20190&lt;/P&gt;&lt;P&gt;Country:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; US&lt;/P&gt;&lt;P&gt;RegDate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2002-07-11&lt;/P&gt;&lt;P&gt;Updated:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-01-03&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ref:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/org/VIO-2"&gt;http://whois.arin.net/rest/org/VIO-2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OrgAbuseHandle: NETWO480-ARIN&lt;/P&gt;&lt;P&gt;OrgAbuseName:&amp;nbsp;&amp;nbsp; Network Admin&lt;/P&gt;&lt;P&gt;OrgAbusePhone:&amp;nbsp; +1-703-948-4300&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OrgAbuseEmail:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:netadmin@verisign.com"&gt;netadmin@verisign.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OrgAbuseRef:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/poc/NETWO480-ARIN"&gt;http://whois.arin.net/rest/poc/NETWO480-ARIN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OrgTechHandle: NETWO480-ARIN&lt;/P&gt;&lt;P&gt;OrgTechName:&amp;nbsp;&amp;nbsp; Network Admin&lt;/P&gt;&lt;P&gt;OrgTechPhone:&amp;nbsp; +1-703-948-4300&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OrgTechEmail:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:netadmin@verisign.com"&gt;netadmin@verisign.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OrgTechRef:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://whois.arin.net/rest/poc/NETWO480-ARIN"&gt;http://whois.arin.net/rest/poc/NETWO480-ARIN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;# ARIN WHOIS data and services are subject to the Terms of Use&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# available at: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.arin.net/whois_tou.html"&gt;https://www.arin.net/whois_tou.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jan 2012 14:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-udp-reverse-path-check/m-p/1810151#M456565</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-01-18T14:52:20Z</dc:date>
    </item>
  </channel>
</rss>

