<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Weird Firewall ACL Log Entry in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/weird-firewall-acl-log-entry/m-p/3798985#M7082</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I'm seeing weird log entries on my firewall. Like this:&lt;/P&gt;
&lt;PRE&gt;2019-02-11 09:22:55	Local6.Notice	192.168.10.10	Feb 11 2019 09:23:03: %ASA-5-106100: access-list VLAN100_access_in permitted tcp VLAN100/172.24.2.163(8021) -&amp;gt; VLAN200/172.24.0.163(51804) hit-cnt 1 first hit [0xa31bbc5d, 0x00000000]&lt;/PRE&gt;
&lt;P&gt;The weird thing is: it looks like it's a reply (since the destination port is a random one). Does anyone have a idea why i'm seeing this traffic in this log rule?&lt;BR /&gt;&lt;BR /&gt;Could this mean that for some reason the host at 172.24.2.163 dropped his former connection and setup a new TCP connection to the host at 172.24.0.163?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:47:52 GMT</pubDate>
    <dc:creator>Eric Snijders</dc:creator>
    <dc:date>2020-02-21T16:47:52Z</dc:date>
    <item>
      <title>Weird Firewall ACL Log Entry</title>
      <link>https://community.cisco.com/t5/network-security/weird-firewall-acl-log-entry/m-p/3798985#M7082</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I'm seeing weird log entries on my firewall. Like this:&lt;/P&gt;
&lt;PRE&gt;2019-02-11 09:22:55	Local6.Notice	192.168.10.10	Feb 11 2019 09:23:03: %ASA-5-106100: access-list VLAN100_access_in permitted tcp VLAN100/172.24.2.163(8021) -&amp;gt; VLAN200/172.24.0.163(51804) hit-cnt 1 first hit [0xa31bbc5d, 0x00000000]&lt;/PRE&gt;
&lt;P&gt;The weird thing is: it looks like it's a reply (since the destination port is a random one). Does anyone have a idea why i'm seeing this traffic in this log rule?&lt;BR /&gt;&lt;BR /&gt;Could this mean that for some reason the host at 172.24.2.163 dropped his former connection and setup a new TCP connection to the host at 172.24.0.163?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-firewall-acl-log-entry/m-p/3798985#M7082</guid>
      <dc:creator>Eric Snijders</dc:creator>
      <dc:date>2020-02-21T16:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Weird Firewall ACL Log Entry</title>
      <link>https://community.cisco.com/t5/network-security/weird-firewall-acl-log-entry/m-p/3799049#M7086</link>
      <description>It could be a number of things.
It does not nesessarily mean that it is reply packet.

If this was the first packet of the tcp session and  if your vlan 100 ip is a indeed a server and the vlan200 is your clients vlan I could asuumed that your server is doing some form of keep-alive/hello messages the previously contaced clients. You need to dig a little more with the operation of your clients/server operation. Wireshark might come in handy</description>
      <pubDate>Mon, 11 Feb 2019 10:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-firewall-acl-log-entry/m-p/3799049#M7086</guid>
      <dc:creator>socratesp1980</dc:creator>
      <dc:date>2019-02-11T10:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Weird Firewall ACL Log Entry</title>
      <link>https://community.cisco.com/t5/network-security/weird-firewall-acl-log-entry/m-p/3799120#M7093</link>
      <description>&lt;P&gt;Hi socratesp1980,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks for the information! Doing a packet capture is no problem, but i'm wondering how i should perform the packet capture. In this case, the VLAN100 IP is indeed the server, and VLAN200 is the client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i would just capture all in and outbound traffic from the server in VLAN100, how would i distinguish this exact traffic? Should i try a capture with the source port in this case? Cause the tcp/8021 is indeed the right traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 11:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/weird-firewall-acl-log-entry/m-p/3799120#M7093</guid>
      <dc:creator>Eric Snijders</dc:creator>
      <dc:date>2019-02-11T11:55:19Z</dc:date>
    </item>
  </channel>
</rss>

