<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA wrong logging information's in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566020#M604922</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the ASDM log viewer I define this filter that show only a range of syslog ID&lt;/P&gt;&lt;P&gt;FILTER:sysID=302000-305000 without including the transaction logs.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you to everybody.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefania&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Dec 2010 15:49:19 GMT</pubDate>
    <dc:creator>stefania.clerici</dc:creator>
    <dc:date>2010-12-14T15:49:19Z</dc:date>
    <item>
      <title>Cisco ASA wrong logging information's</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566014#M604904</link>
      <description>&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Tabella normale";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;SPAN style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;We have a Cisco ASA 5510 and is running fine.&lt;BR /&gt; On the ASDM interface the log show the correct source ip address but as destination address we get always the ASA outside IP address instead of the real destination ip address.&lt;BR /&gt; We try to find a settings on the ASDM but we couldn't.&lt;BR /&gt; Any idea?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:21:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566014#M604904</guid>
      <dc:creator>stefania.clerici</dc:creator>
      <dc:date>2019-03-11T19:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA wrong logging information's</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566015#M604908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please kindly check which syslog number you are referring too.&lt;/P&gt;&lt;P&gt;By the sounds of it, it seems that you are looking at NAT translation logs, that is why you are getting the ASA outside interface instead of the destination ip address because it is logging the translation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 12:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566015#M604908</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-12-14T12:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA wrong logging information's</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566016#M604915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;syslog id numbers are 305011 and 305012.&lt;/P&gt;&lt;P&gt;How can I set the ASA to get the traffic log and not the transactions log on my ASDM?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 12:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566016#M604915</guid>
      <dc:creator>stefania.clerici</dc:creator>
      <dc:date>2010-12-14T12:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA wrong logging information's</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566017#M604916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Stefania&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those logs that you are getting are the ones for the translation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="pEM_ErrMsg"&gt;ASA-6-305011: Built {dynamic|static} {TCP|UDP|ICMP} translation from &lt;BR /&gt;&lt;EM class="cEmphasis"&gt;interface_name&lt;/EM&gt;:&lt;EM class="cEmphasis"&gt;real_address&lt;/EM&gt;&lt;EM class="cCi_CmdItalic" style="font-style: italic;"&gt;/&lt;/EM&gt;&lt;SPAN style="color: black; font-style: oblique; font-weight: normal;"&gt;real_port&lt;/SPAN&gt; to &lt;BR /&gt;&lt;EM class="cEmphasis"&gt;interface_name&lt;/EM&gt;:&lt;EM class="cEmphasis"&gt;mapped_address&lt;/EM&gt;&lt;EM class="cCi_CmdItalic" style="font-style: italic;"&gt;/&lt;/EM&gt;&lt;SPAN style="color: black; font-style: oblique; font-weight: normal;"&gt;mapped_port&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically this happens everytime that a computer tries to do a connection to a webpage, skype or any other service on any other interface of the firewall. Since this is just the translation log, you will see that the NAT has been done for the real host to the mapped IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The one that you would need to check (in case you want to see the real address of the host doing a connection to the outside world) is the one with the built tcp connection &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="pEM_ErrMsg"&gt;%ASA-6-302013: Built {inbound|outbound} TCP &lt;EM class="cEmphasis"&gt;connection_id&lt;/EM&gt; for &lt;EM class="cEmphasis"&gt;interface&lt;/EM&gt;:&lt;EM class="cEmphasis"&gt;real-address&lt;/EM&gt;/&lt;EM class="cEmphasis"&gt;real-port&lt;/EM&gt; &lt;BR /&gt;(&lt;EM class="cEmphasis"&gt;mapped-address/mapped-port&lt;/EM&gt;) to &lt;BR /&gt;&lt;EM class="cEmphasis"&gt;interface&lt;/EM&gt;:&lt;EM class="cEmphasis"&gt;real-address&lt;/EM&gt;/&lt;EM class="cEmphasis"&gt;real-port&lt;/EM&gt; (&lt;EM class="cEmphasis"&gt;mapped-address/mapped-port&lt;/EM&gt;) [(&lt;EM class="cEmphasis"&gt;user&lt;/EM&gt;)]&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;This one will give you the information of the host that is doing a connection and where is he heading to. &lt;BR /&gt;&lt;BR /&gt;The other one just tells you which NAT did he use in order to go there. &lt;BR /&gt;&lt;BR /&gt;Cheers &lt;BR /&gt;&lt;BR /&gt;Mike &lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 13:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566017#M604916</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-12-14T13:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA wrong logging information's</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566018#M604918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mike,&lt;/P&gt;&lt;P&gt;is it possible to filter the logs in order to get only the traffic logs (TCP and UDP) without the transaction logs?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Stefania&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 14:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566018#M604918</guid>
      <dc:creator>stefania.clerici</dc:creator>
      <dc:date>2010-12-14T14:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA wrong logging information's</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566019#M604920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASDM I am uncertain &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt; for not saying no.... BUT &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&amp;nbsp; If you have a syslog server (which you can get one free online), you can create a logging list and put the log ID that you want in order to receive the logs that you want and exlude the ones with the translation on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need more info let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 15:07:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566019#M604920</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-12-14T15:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA wrong logging information's</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566020#M604922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the ASDM log viewer I define this filter that show only a range of syslog ID&lt;/P&gt;&lt;P&gt;FILTER:sysID=302000-305000 without including the transaction logs.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you to everybody.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefania&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 15:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-wrong-logging-information-s/m-p/1566020#M604922</guid>
      <dc:creator>stefania.clerici</dc:creator>
      <dc:date>2010-12-14T15:49:19Z</dc:date>
    </item>
  </channel>
</rss>

