<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Syslogs errors in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-syslogs-errors/m-p/828305#M495037</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as your device is blocking these port scanning/reconnaisance attempts, it means its working as it should.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first log message is how the device responds or protects for spoofing attempts using Unicast RPF (Reverse Path Forwarding)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will appear if you ahve the command "ip verify reverse-path" enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other logs are attempts to connect to the Public IP you have 82.178.21.28 on port 1076. This can be ignored as long as it blocks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not want an entry added for this message you can give "no logging 106023".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Oct 2007 12:49:31 GMT</pubDate>
    <dc:creator>jaravinthan</dc:creator>
    <dc:date>2007-10-30T12:49:31Z</dc:date>
    <item>
      <title>PIX Syslogs errors</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslogs-errors/m-p/828304#M495032</link>
      <description>&lt;P&gt;I have PIX  515E with 2 interface, inside, outside, I have PAT from inside - outside and NAT from outside to inside.&lt;/P&gt;&lt;P&gt;I have installed CISCO ASDM, when I am monitoring the status syslog and droped packet rates I found that, ACL drop packet rate is very high, and I have too much syslogs messages for the following errors.&lt;/P&gt;&lt;P&gt;1	Oct 30 2007	11:57:32	106021	10.3.10.4	17.254.0.31	Deny UDP reverse path check from 10.3.10.4 to 17.254.0.31 on interface inside&lt;/P&gt;&lt;P&gt;						&lt;/P&gt;&lt;P&gt;						&lt;/P&gt;&lt;P&gt;4	Oct 30 2007	11:35:56	106023	218.174.106.1	82.178.21.28	Deny udp src outside:218.174.106.1/27753 dst inside:82.178.21.28/1076 by access-group "outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;						&lt;/P&gt;&lt;P&gt;4	Oct 30 2007	11:35:55	106023	60.237.167.133	82.178.21.28	Deny udp src outside:60.237.167.133/7348 dst inside:82.178.21.28/1076 by access-group "outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;4	Oct 30 2007	11:35:55	106023	222.77.116.18	82.178.21.28	Deny udp src outside:222.77.116.18/49154 dst inside:82.178.21.28/1076 by access-group "outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to solve it ??&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslogs-errors/m-p/828304#M495032</guid>
      <dc:creator>reagentom</dc:creator>
      <dc:date>2020-02-21T09:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Syslogs errors</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslogs-errors/m-p/828305#M495037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as your device is blocking these port scanning/reconnaisance attempts, it means its working as it should.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first log message is how the device responds or protects for spoofing attempts using Unicast RPF (Reverse Path Forwarding)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will appear if you ahve the command "ip verify reverse-path" enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other logs are attempts to connect to the Public IP you have 82.178.21.28 on port 1076. This can be ignored as long as it blocks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not want an entry added for this message you can give "no logging 106023".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2007 12:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslogs-errors/m-p/828305#M495037</guid>
      <dc:creator>jaravinthan</dc:creator>
      <dc:date>2007-10-30T12:49:31Z</dc:date>
    </item>
  </channel>
</rss>

