<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: only one event triggered in cascade multiple context ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/only-one-event-triggered-in-cascade-multiple-context-asa/m-p/3417672#M925785</link>
    <description>&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;its expected behavior. Firepower module is not fully aware of the context on ASA so traffic might travel through the module more than once which will be logged more than once.&lt;/P&gt;
&lt;P&gt;But for the intrusion events, it will be only one event for&amp;nbsp; duplicate traffic which will logged only once for intrusion event.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jul 2018 17:19:58 GMT</pubDate>
    <dc:creator>yogdhanu</dc:creator>
    <dc:date>2018-07-18T17:19:58Z</dc:date>
    <item>
      <title>only one event triggered in cascade multiple context ASA</title>
      <link>https://community.cisco.com/t5/network-security/only-one-event-triggered-in-cascade-multiple-context-asa/m-p/3417510#M925784</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a pair of ASA 5585-X with Firepower ssp-60. They are deployed in multiple context mode, and the contexts are connected in cascade (traffic passes through multiple contexts).&lt;/P&gt;
&lt;P&gt;All connections are logged twice in FMC, once on each context that logs the connection.&lt;/P&gt;
&lt;P&gt;But when an attack is detected, only one event is generated, on one of the contexts.&lt;/P&gt;
&lt;P&gt;So is this a normal/expected behavior or&amp;nbsp; we have to do some adjustments?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/only-one-event-triggered-in-cascade-multiple-context-asa/m-p/3417510#M925784</guid>
      <dc:creator>borutlape</dc:creator>
      <dc:date>2020-02-21T15:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: only one event triggered in cascade multiple context ASA</title>
      <link>https://community.cisco.com/t5/network-security/only-one-event-triggered-in-cascade-multiple-context-asa/m-p/3417672#M925785</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;its expected behavior. Firepower module is not fully aware of the context on ASA so traffic might travel through the module more than once which will be logged more than once.&lt;/P&gt;
&lt;P&gt;But for the intrusion events, it will be only one event for&amp;nbsp; duplicate traffic which will logged only once for intrusion event.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 17:19:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/only-one-event-triggered-in-cascade-multiple-context-asa/m-p/3417672#M925785</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-07-18T17:19:58Z</dc:date>
    </item>
  </channel>
</rss>

