<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deny inbound protocol 41 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775992#M533116</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message means that the ASA is dropping this connection since it failed a security check. Too many unwanted syslogs can affect other resources like CPU, etc. If you are not aware of the IP address 94.245.121.211, just shun this IP with command "shun 94.245.121.211". This will drop all packets from this source without processing it against any checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Please mark this question as answered if it has been resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Aug 2011 07:36:54 GMT</pubDate>
    <dc:creator>Anu M Chacko</dc:creator>
    <dc:date>2011-08-19T07:36:54Z</dc:date>
    <item>
      <title>Deny inbound protocol 41</title>
      <link>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775991#M533114</link>
      <description>&lt;P&gt;Recently I've started getting absolutely hundreds of protocol 41 deny alarms on my ASA firewall outside interface. These are flooding my syslog and making it hard to check for other issues that may be going on in our network.&lt;/P&gt;&lt;P&gt;Most are from 94.245.121.x addresses which appear to be owned by Microsoft!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;&lt;EM&gt;19-08-2011&amp;nbsp;&amp;nbsp;&amp;nbsp; 08:22:34&amp;nbsp;&amp;nbsp;&amp;nbsp; Local4.Error&amp;nbsp;&amp;nbsp;&amp;nbsp; firewall1&amp;nbsp;&amp;nbsp;&amp;nbsp; %ASA-3-106010: Deny inbound protocol 41 src internet:94.245.121.211 dst internet:x.x.x.x&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help me understand these alerts better? Should I be concerned?&lt;/P&gt;&lt;P&gt;Protocol 41 seems to be IPv6 to IPv4 tunneling protocol (6in4).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775991#M533114</guid>
      <dc:creator>handsy</dc:creator>
      <dc:date>2019-03-11T21:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Deny inbound protocol 41</title>
      <link>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775992#M533116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message means that the ASA is dropping this connection since it failed a security check. Too many unwanted syslogs can affect other resources like CPU, etc. If you are not aware of the IP address 94.245.121.211, just shun this IP with command "shun 94.245.121.211". This will drop all packets from this source without processing it against any checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Please mark this question as answered if it has been resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 07:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775992#M533116</guid>
      <dc:creator>Anu M Chacko</dc:creator>
      <dc:date>2011-08-19T07:36:54Z</dc:date>
    </item>
    <item>
      <title>Deny inbound protocol 41</title>
      <link>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775993#M533118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for quick reply, but I guess what I'm after is someone to tell me why Microsoft IP addresses are constantly hitting my firewall on protocol 41?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 08:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775993#M533118</guid>
      <dc:creator>handsy</dc:creator>
      <dc:date>2011-08-19T08:17:11Z</dc:date>
    </item>
    <item>
      <title>Deny inbound protocol 41</title>
      <link>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775994#M533122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a host on the inside that is has an application that uses the 6to4 protocol? It is possible that there is, which requests this kind of traffic or to open ports. I suggest you track down that host and disable the application if you don't need it. Here's a good link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.ipv6tf.org/index.php?page=using/connectivity/6to4"&gt;http://www.ipv6tf.org/index.php?page=using/connectivity/6to4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Please mark this question as answered if it has been resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 08:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-inbound-protocol-41/m-p/1775994#M533122</guid>
      <dc:creator>Anu M Chacko</dc:creator>
      <dc:date>2011-08-19T08:31:00Z</dc:date>
    </item>
  </channel>
</rss>

