<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Scanning logs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-scanning-logs/m-p/1135693#M896740</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you issue the command : sh run all,you can see the default configuration which you do not normally see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would see :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection rate scanning-threat rate-interval 3600 average-rate 4 burst-rate 8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which suggests the parameters for the " threat detection scanning threat feature ".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are getting too much of logs :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Disable threat detection altogether.The memory usage will also come down considerably when you do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Change the parameters by running the above command with different values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see that there is a match in burst rate value,so increase that to ,let's say 10.&lt;/P&gt;&lt;P&gt;I also see average configured rate is 4 and your f/w is seeing traffic of avg. rate of 8.So,change it to 10 or 12.That should take care of log messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last,disable the message itself so that you do n't see it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no logging message &lt;ID&gt;&lt;/ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Sep 2008 14:39:00 GMT</pubDate>
    <dc:creator>suschoud</dc:creator>
    <dc:date>2008-09-08T14:39:00Z</dc:date>
    <item>
      <title>ASA Scanning logs</title>
      <link>https://community.cisco.com/t5/network-security/asa-scanning-logs/m-p/1135691#M896735</link>
      <description>&lt;P&gt;Hi can anyone explain the below. We have just installed ASA5550 ver 8.0.3 and replace a pix 525 and we are recieving these message alot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[ Scanning] drop rate-2 exceeded. Current burst rate is 8 per second, max configured rate is 8; Current average rate is 8 per second, max configured rate is 4; Cumulative total count is 29362&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:41:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-scanning-logs/m-p/1135691#M896735</guid>
      <dc:creator>network_team</dc:creator>
      <dc:date>2019-03-11T13:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Scanning logs</title>
      <link>https://community.cisco.com/t5/network-security/asa-scanning-logs/m-p/1135692#M896737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like threat-detection is enabled and configured to allow a burst rate of 4kbps.  Can you post a running-configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00809763ea.shtml#sol6" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00809763ea.shtml#sol6&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Sep 2008 14:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-scanning-logs/m-p/1135692#M896737</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2008-09-08T14:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Scanning logs</title>
      <link>https://community.cisco.com/t5/network-security/asa-scanning-logs/m-p/1135693#M896740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you issue the command : sh run all,you can see the default configuration which you do not normally see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would see :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection rate scanning-threat rate-interval 3600 average-rate 4 burst-rate 8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which suggests the parameters for the " threat detection scanning threat feature ".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are getting too much of logs :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Disable threat detection altogether.The memory usage will also come down considerably when you do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Change the parameters by running the above command with different values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see that there is a match in burst rate value,so increase that to ,let's say 10.&lt;/P&gt;&lt;P&gt;I also see average configured rate is 4 and your f/w is seeing traffic of avg. rate of 8.So,change it to 10 or 12.That should take care of log messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last,disable the message itself so that you do n't see it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no logging message &lt;ID&gt;&lt;/ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Sep 2008 14:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-scanning-logs/m-p/1135693#M896740</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2008-09-08T14:39:00Z</dc:date>
    </item>
  </channel>
</rss>

