<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic send alarm cisco asa 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717638#M558003</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a cisco asa 5510.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am doing attack a my firewall, using namp. I am seeing in the log the attack but i like that firewall send only alarm of attack by email or nagios. I have active email with warning and i received very much email.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I observed that graph show attack, but not ip of attacker, is possible that cisco asa show the ip too ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log show scanning with nmap but not shunning IP and not send alarm. How i can send alarm ?&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/6/0/39063-cisco-foro.png" alt="cisco-foro.png" class="jive-image-thumbnail jive-image" height="45" onclick="" width="796" /&gt;&lt;/P&gt;&lt;P&gt;The graph no show ip, it's possible show it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/6/0/39064-cisco-grafica.png" alt="cisco-grafica.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="almost_half_cell" id="gt-res-content"&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;In short&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;as&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;I can&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;detect&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;attacks&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;send&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;me&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;warning&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;Configuration threat-detection&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;ciscoasa# show running-config | i shu&lt;BR /&gt;threat-detection scanning-threat shun except ip-address X.X.X.X 255.255.255.0&lt;BR /&gt;threat-detection scanning-threat shun duration 3600&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;Thank very much.&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;P&gt;&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Tabla normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;SPAN style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&lt;IMG height="24" src="https://community.cisco.com/" width="408" /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:20:08 GMT</pubDate>
    <dc:creator>emilioj.romero</dc:creator>
    <dc:date>2019-03-11T20:20:08Z</dc:date>
    <item>
      <title>send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717638#M558003</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a cisco asa 5510.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am doing attack a my firewall, using namp. I am seeing in the log the attack but i like that firewall send only alarm of attack by email or nagios. I have active email with warning and i received very much email.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I observed that graph show attack, but not ip of attacker, is possible that cisco asa show the ip too ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log show scanning with nmap but not shunning IP and not send alarm. How i can send alarm ?&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/6/0/39063-cisco-foro.png" alt="cisco-foro.png" class="jive-image-thumbnail jive-image" height="45" onclick="" width="796" /&gt;&lt;/P&gt;&lt;P&gt;The graph no show ip, it's possible show it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/6/0/39064-cisco-grafica.png" alt="cisco-grafica.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="almost_half_cell" id="gt-res-content"&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;In short&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;as&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;I can&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;detect&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;attacks&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;send&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;me&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;warning&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;Configuration threat-detection&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;ciscoasa# show running-config | i shu&lt;BR /&gt;threat-detection scanning-threat shun except ip-address X.X.X.X 255.255.255.0&lt;BR /&gt;threat-detection scanning-threat shun duration 3600&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;Thank very much.&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;P&gt;&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Tabla normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;SPAN style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&lt;IMG height="24" src="https://community.cisco.com/" width="408" /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717638#M558003</guid>
      <dc:creator>emilioj.romero</dc:creator>
      <dc:date>2019-03-11T20:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717639#M558004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emilio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you could show me your logging configuration, then i can tell you the exact commands that need to be configured.&lt;/P&gt;&lt;P&gt;However, primarily, you need to see to it that the syslog 401002 is in the logging list. By default the syslog is logged at level 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the description for syslog 401002:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="pEM_ErrMsg"&gt;&lt;SPAN class="cBoldNormal"&gt;Error Message&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; %ASA-4-401002: Shun added: IP_address&lt;EM class="cEmphasis"&gt; IP_address &lt;/EM&gt;port&lt;EM class="cEmphasis"&gt; port&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;SPAN class="cBoldNormal"&gt;Explanation&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; A &lt;STRONG class="cBold"&gt;shun&lt;/STRONG&gt; command was entered, where the first IP address is the shunned host. The other&amp;nbsp; addresses and ports are optional and are used to terminate the connection if available.&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;Hope this helps.&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;-Shrikant&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;P.S.: Please mark the question as answered if it has been resolved. Do rate helpful posts. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Apr 2011 11:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717639#M558004</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-13T11:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717640#M558005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list errores level errors&lt;BR /&gt;logging buffer-size 32768&lt;BR /&gt;logging buffered warnings&lt;BR /&gt;logging trap warnings&lt;BR /&gt;logging asdm warnings&lt;BR /&gt;logging from-address xxxxx@xxxxxx&lt;BR /&gt;logging recipient-address xxxxx@jxxxxxx level errors&lt;BR /&gt;logging host Interface-outside 10.xx.xx.xx&lt;BR /&gt;logging message 605004 level warnings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall no shunning host, only detect scanning, and&lt;/P&gt;&lt;DIV class="almost_half_cell" id="gt-res-content"&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;would like&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;to&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;send&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;alerts&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;or&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;email&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;Shunn&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Haz clic para obtener otras posibles traducciones"&gt;ip&lt;/SPAN&gt;&lt;SPAN title="Haz clic para obtener otras posibles traducciones"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 06:29:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717640#M558005</guid>
      <dc:creator>emilioj.romero</dc:creator>
      <dc:date>2011-04-14T06:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717641#M558006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you need more information about&amp;nbsp; my service request?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking forward for you reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Emilio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Apr 2011 21:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717641#M558006</guid>
      <dc:creator>emilioj.romero</dc:creator>
      <dc:date>2011-04-15T21:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717642#M558007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emilio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wrong with the syslog I mentioned earlier. That syslog was for when "shun &lt;IP&gt;" is given in the command line.&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The syslog you should be looking out for is 733102&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="pEM_ErrMsg"&gt;&lt;SPAN class="cBoldNormal"&gt;Error Message&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; %ASA-4-733102:Threat-detection adds host &lt;EM class="cEmphasis"&gt;%I&lt;/EM&gt; to shun list &lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;A name="wp5299541"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;SPAN class="cBoldNormal"&gt;Explanation&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt; This message indicates that a host has been shunned by the threat detection engine.&amp;nbsp; When the &lt;STRONG class="cCN_CmdName"&gt;threat-detection scanning-threat shun&lt;/STRONG&gt; command is configured, the attacking hosts will&amp;nbsp; be shunned by the threat detection engine.&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;Now, as to why the host is not being shunned, you can check the following:&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;Do "&lt;STRONG&gt;show run all | in scanning&lt;/STRONG&gt;" to get the scanning threat rate parameters set on the ASA.&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;Enable "&lt;STRONG&gt;threat-detection statistics host&lt;/STRONG&gt;".&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;Note: this command can effect the performance of the ASA in a high load environment. So make sure you disable it once you are done with it.&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;Let the ASA collect statistics for the attacking host for some time.&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;You can now view the statistics for the attacker by doing: "&lt;STRONG&gt;show threat-detection statistics host &lt;IP address=""&gt;&lt;/IP&gt;&lt;/STRONG&gt;" and see if the statistics for the&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;host exceed the scanning threat rate parameters or not. Unless it exceeds that it won't be shunned.&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;You can go ahead and tweak the parameters for the scanning rate with the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG class="cBold"&gt;threat-detection rate scanning-threat rate-interval &lt;TIME&gt; average-rate &lt;DROPS&gt; burst-rate &lt;DROPS&gt;&lt;BR /&gt;&lt;/DROPS&gt;&lt;/DROPS&gt;&lt;/TIME&gt;&lt;/STRONG&gt;&lt;SPAN class="cBold"&gt;(Burst-rate duration is 1/30th of the rate-interval)&lt;BR /&gt;(Make sure you remove the earlier configured scanned rates, just in case)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ASA shuns the attacker, you can view it under "&lt;STRONG&gt;show threat-detection shun&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark the question as answered, if it ha been resolved. Do rate helpful posts. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Apr 2011 19:22:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717642#M558007</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-16T19:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717643#M558013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The steps which you explain before have been made by me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need send an email or trap when an attack happens. How to get it? Could you explain to me what steps I have to make, please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you need the configuration file of my firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Emilio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Apr 2011 20:10:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717643#M558013</guid>
      <dc:creator>emilioj.romero</dc:creator>
      <dc:date>2011-04-17T20:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717644#M558015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emilio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging message 733102 level 0&lt;/P&gt;&lt;P&gt;logging mail 0&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;logging from-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:aaaa@bbbb.com"&gt;aaaa@bbbb.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;logging recipient-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:xxxx@yyyy.com"&gt;xxxx@yyyy.com&lt;/A&gt;&lt;SPAN&gt; level 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;smtp-server &lt;YOUR mail="" server="" ip=""&gt;&lt;/YOUR&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This way you will get alerts on &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:xxxx@yyyy.com"&gt;xxxx@yyyy.com&lt;/A&gt;&lt;SPAN&gt; whenever the syslog 733102 is generated. The from address in the email will be &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:aaaa@bbbb.com"&gt;aaaa@bbbb.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark the question as answered if it has been resolved. Do rate helpful posts. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Apr 2011 20:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717644#M558015</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-17T20:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717645#M558016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: black; font-size: 12pt; background: white; font-family: Times New Roman; "&gt;I tested your configuration and it doesn’t work properly&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: black; font-size: 12pt; background: white; font-family: Times New Roman; "&gt;I attach you the configuration file and loggin.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: black; font-size: 12pt; background: white; font-family: Times New Roman; "&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/6/7/45762-logging.png" class="jive-image" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: black; font-size: 12pt; background: white; font-family: Times New Roman; "&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list errores level errors&lt;BR /&gt;logging buffer-size 32768&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap warnings&lt;BR /&gt;logging asdm warnings&lt;BR /&gt;logging mail emergencies&lt;BR /&gt;logging from-address xxxx&lt;A href="https://community.cisco.com/"&gt;@xxxx&lt;/A&gt;&lt;BR /&gt;logging recipient-address xxxxx&lt;A href="https://community.cisco.com/"&gt;@xxxxx&lt;/A&gt; level emergencies&lt;BR /&gt;logging host AAAA X.X.X.X&lt;BR /&gt;logging message 733102 level emergencies&lt;BR /&gt;logging message 605004 level warnings&lt;BR /&gt;smtp-server X.X.X.X&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: black; font-size: 12pt; background: white; font-family: Times New Roman; "&gt;Launch nmap (Scanning)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/7/7/45771-nmap.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P&gt;Do you need more information about&amp;nbsp; my service request?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: black; font-size: 12pt; background: white; font-family: Times New Roman; "&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Apr 2011 09:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717645#M558016</guid>
      <dc:creator>emilioj.romero</dc:creator>
      <dc:date>2011-04-18T09:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717646#M558017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emilio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought you needed an email alert when a host was shunned.&lt;/P&gt;&lt;P&gt;If you need an alert whenever [Scanning] drop rate-l is exceeded, then please add the following command:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging message 733100 level 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASDM, you will be able to see the syslog id for all logs that are generated. So any log you want to be alerted by email, do: logging message &lt;LOG id=""&gt; level 0&lt;/LOG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark the question as answered if it has been resolved. Do rate helpful posts. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Apr 2011 13:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717646#M558017</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-18T13:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717647#M558018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #ffffff;" title="Es correcto, muchas gracias, pero como puedo conocer la ip del atacante."&gt;That's right, thank you very much, but how can i know the ip of attacker?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Apr 2011 09:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717647#M558018</guid>
      <dc:creator>emilioj.romero</dc:creator>
      <dc:date>2011-04-20T09:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: send alarm cisco asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717648#M558019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you need more information about&amp;nbsp; my service request?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking forward for you reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Emilio&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Apr 2011 21:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-alarm-cisco-asa-5510/m-p/1717648#M558019</guid>
      <dc:creator>emilioj.romero</dc:creator>
      <dc:date>2011-04-26T21:40:40Z</dc:date>
    </item>
  </channel>
</rss>

