06-18-2013 01:19 PM
Hi All,
I got the following logs from the syslog server. My Ciscoworks LMS 4.2.2 (IP 10.26.73.1) keeps sending icmp to 128.100.3.221 and generated tons of logs. I checked the Ciscoworks but couldn't locate the IP of 128.100.3.221. Please help me stop the ICMP on the Ciscoworks. Thanks in advance.
1 2013/06/18 15:12:33.839 EDT 10.26.0.9 Jun 18 2013 15:12:31: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
2 2013/06/18 15:12:42.105 EDT 10.26.0.9 Jun 18 2013 15:12:39: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
3 2013/06/18 15:12:44.918 EDT 10.26.0.9 Jun 18 2013 15:12:42: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
4 2013/06/18 15:12:49.512 EDT 10.26.0.9 Jun 18 2013 15:12:46: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
5 2013/06/18 15:13:18.562 EDT 10.26.0.9 Jun 18 2013 15:13:15: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
6 2013/06/18 15:13:19.234 EDT 10.26.0.9 Jun 18 2013 15:13:16: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
7 2013/06/18 15:13:30.985 EDT 10.26.0.9 Jun 18 2013 15:13:28: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
8 2013/06/18 15:13:31.361 EDT 10.26.0.9 Jun 18 2013 15:13:28: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
9 2013/06/18 15:13:52.144 EDT 10.26.0.9 Jun 18 2013 15:13:49: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
10 2013/06/18 15:13:59.692 EDT 10.26.0.9 Jun 18 2013 15:13:57: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
11 2013/06/18 15:14:33.727 EDT 10.26.0.9 Jun 18 2013 15:14:31: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
12 2013/06/18 15:14:42.103 EDT 10.26.0.9 Jun 18 2013 15:14:39: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
13 2013/06/18 15:14:45.697 EDT 10.26.0.9 Jun 18 2013 15:14:43: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
14 2013/06/18 15:14:49.213 EDT 10.26.0.9 Jun 18 2013 15:14:46: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
15 2013/06/18 15:15:19.169 EDT 10.26.0.9 Jun 18 2013 15:15:16: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
16 2013/06/18 15:15:19.294 EDT 10.26.0.9 Jun 18 2013 15:15:16: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
17 2013/06/18 15:15:30.467 EDT 10.26.0.9 Jun 18 2013 15:15:27: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
18 2013/06/18 15:15:31.592 EDT 10.26.0.9 Jun 18 2013 15:15:28: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
19 2013/06/18 15:15:52.673 EDT 10.26.0.9 Jun 18 2013 15:15:50: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
20 2013/06/18 15:15:59.720 EDT 10.26.0.9 Jun 18 2013 15:15:57: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)
21 2013/06/18 15:16:34.334 EDT 10.26.0.9 Jun 18 2013 15:16:31: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
22 2013/06/18 15:16:42.428 EDT 10.26.0.9 Jun 18 2013 15:16:39: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)
06-18-2013 10:58 PM
DFM, the faultmanagement component uses ICMP by default.
It is designed to do so and you cannot turn this off in the LMS webGUI.
If you turn faultmanagement off I think 99% of the ICMP will be gone.
Cheers,
Michel
06-20-2013 07:41 AM
Thanks for the reply.
How can I find this IP from DFM and remove it so that Ciscoworks will stop sending the icmp packets?
06-20-2013 11:48 AM
You can unmanage or remanage device components using the Detailed Device View (cards, interfaces, ports, IP addresses, and so forth). If you unmanage a component, LMS will ignore subsequent events (including traps).
You can check the details here :
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide