<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log shows wrong source/destination, need help! (ASA 8.3) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692577#M561738</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the remote end sends a reset packet to prevent the TCP 3-way handshake from completing, the ASA is going to log the source of the reset.&amp;nbsp; This is expected behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 May 2011 17:11:44 GMT</pubDate>
    <dc:creator>Allen P Chen</dc:creator>
    <dc:date>2011-05-31T17:11:44Z</dc:date>
    <item>
      <title>log shows wrong source/destination, need help! (ASA 8.3)</title>
      <link>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692574#M561731</link>
      <description>&lt;P&gt;The Cisco ASDM or the event manager show wrong source/destination for teardown tcp messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this example the communication is an ssh session;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from 1.1.1.1 -&amp;gt; 2.2.2.2 ssh and the connection is reseted by 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message build outbound is correct, i.e. source is 1.1.1.1 (message id is 302013)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;May 26 2011&lt;/TD&gt;&lt;TD&gt;11:27:57&lt;/TD&gt;&lt;TD&gt;302013&lt;/TD&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;54046&lt;/TD&gt;&lt;TD&gt;2.2.2.2&lt;/TD&gt;&lt;TD&gt;22&lt;/TD&gt;&lt;TD&gt;Built outbound TCP connection 575077 for integration:2.2.2.2/22 (2.2.2.2/22) to panalpina:1.1.1.1/54046 (1.1.1.1/54046)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the teardown is incorrect, i.e.&lt;STRONG style="color: #ff0000; "&gt; source for the connection is 2.2.2.2 which is definitely not true&lt;/STRONG&gt; (message id is 302014)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;May 26 2011&lt;/TD&gt;&lt;TD&gt;11:27:57&lt;/TD&gt;&lt;TD&gt;302014&lt;/TD&gt;&lt;TD&gt;&lt;STRONG style="color: #ff0000; "&gt;2.2.2.2&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;22&lt;/TD&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;54046&lt;/TD&gt;&lt;TD&gt;Teardown TCP connection 575077 for integration:2.2.2.2/22 to panalpina:1.1.1.1/54046 duration 0:00:00 bytes 0 TCP Reset-O&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also there seems to be a documentation bug in syslog messages for ASA 8.4 since the message for the teardown 302014 is gone!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692574#M561731</guid>
      <dc:creator>pweichmann</dc:creator>
      <dc:date>2019-03-11T20:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: log shows wrong source/destination, need help! (ASA 8.3)</title>
      <link>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692575#M561733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log ID 302014 is available under the log message guide for both software versions 8.3 and 8.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8.3&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4770614"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4770614&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8.4&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/system/message/logmsgs.html#wp6941209"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/system/message/logmsgs.html#wp6941209&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the teardown message, the SSH server at 2.2.2.2 is resetting the connection (the log message indicates the reset is coming from the Outside, TCP Reset-O).&amp;nbsp; If the SSH server is sending the reset, then the source of the reset packet from host 2.2.2.2 should be correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 May 2011 17:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692575#M561733</guid>
      <dc:creator>Allen P Chen</dc:creator>
      <dc:date>2011-05-26T17:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: log shows wrong source/destination, need help! (ASA 8.3)</title>
      <link>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692576#M561735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks. It looks like the 302014 is only missing in the pdf where the 302015 follows the 302013 message &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm used to think that all messages pertaining to a stateful packet inspection session should be shown as the same source ip/port and dest ip/port direction and not show that a RST packet has been sent by the other side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A.1026 - B.22&amp;nbsp;&amp;nbsp; SYN&lt;/P&gt;&lt;P&gt;B.22&amp;nbsp; - A.1026&amp;nbsp;&amp;nbsp; RST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually this is tracked only as a communication of A.1026 -&amp;gt; B.22.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This must be a bug, no?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2011 12:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692576#M561735</guid>
      <dc:creator>pweichmann</dc:creator>
      <dc:date>2011-05-30T12:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: log shows wrong source/destination, need help! (ASA 8.3)</title>
      <link>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692577#M561738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the remote end sends a reset packet to prevent the TCP 3-way handshake from completing, the ASA is going to log the source of the reset.&amp;nbsp; This is expected behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 17:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-shows-wrong-source-destination-need-help-asa-8-3/m-p/1692577#M561738</guid>
      <dc:creator>Allen P Chen</dc:creator>
      <dc:date>2011-05-31T17:11:44Z</dc:date>
    </item>
  </channel>
</rss>

