cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
739
Views
5
Helpful
3
Replies

Ciscoworks LMS 4.2.2 keeps sending icmp to a specific IP

robert.huang
Level 1
Level 1

Hi All,

I got the following logs from the syslog server. My Ciscoworks LMS 4.2.2 (IP 10.26.73.1) keeps sending icmp to 128.100.3.221 and generated tons of logs. I checked the Ciscoworks but couldn't locate the IP of 128.100.3.221. Please help me stop the ICMP on the Ciscoworks. Thanks in advance.

1                            2013/06/18 15:12:33.839 EDT            10.26.0.9               Jun 18 2013 15:12:31: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

2                            2013/06/18 15:12:42.105 EDT            10.26.0.9               Jun 18 2013 15:12:39: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

3                            2013/06/18 15:12:44.918 EDT            10.26.0.9               Jun 18 2013 15:12:42: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

4                            2013/06/18 15:12:49.512 EDT            10.26.0.9               Jun 18 2013 15:12:46: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

5                            2013/06/18 15:13:18.562 EDT            10.26.0.9               Jun 18 2013 15:13:15: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

6                            2013/06/18 15:13:19.234 EDT            10.26.0.9               Jun 18 2013 15:13:16: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

7                            2013/06/18 15:13:30.985 EDT            10.26.0.9               Jun 18 2013 15:13:28: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

8                            2013/06/18 15:13:31.361 EDT            10.26.0.9               Jun 18 2013 15:13:28: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

9                            2013/06/18 15:13:52.144 EDT            10.26.0.9               Jun 18 2013 15:13:49: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

10                          2013/06/18 15:13:59.692 EDT            10.26.0.9               Jun 18 2013 15:13:57: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

11                          2013/06/18 15:14:33.727 EDT            10.26.0.9               Jun 18 2013 15:14:31: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

12                          2013/06/18 15:14:42.103 EDT            10.26.0.9               Jun 18 2013 15:14:39: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

13                          2013/06/18 15:14:45.697 EDT            10.26.0.9               Jun 18 2013 15:14:43: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

14                          2013/06/18 15:14:49.213 EDT            10.26.0.9               Jun 18 2013 15:14:46: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

15                          2013/06/18 15:15:19.169 EDT            10.26.0.9               Jun 18 2013 15:15:16: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

16                          2013/06/18 15:15:19.294 EDT            10.26.0.9               Jun 18 2013 15:15:16: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

17                          2013/06/18 15:15:30.467 EDT            10.26.0.9               Jun 18 2013 15:15:27: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

18                          2013/06/18 15:15:31.592 EDT            10.26.0.9               Jun 18 2013 15:15:28: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

19                          2013/06/18 15:15:52.673 EDT            10.26.0.9               Jun 18 2013 15:15:50: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

20                          2013/06/18 15:15:59.720 EDT            10.26.0.9               Jun 18 2013 15:15:57: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.205 (type 8, code 0)

21                          2013/06/18 15:16:34.334 EDT            10.26.0.9               Jun 18 2013 15:16:31: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

22                          2013/06/18 15:16:42.428 EDT            10.26.0.9               Jun 18 2013 15:16:39: %ASA-3-106014: Deny inbound icmp src inside:10.26.73.1 dst inside:128.100.3.221 (type 8, code 0)

3 Replies 3

Michel Hegeraat
Level 7
Level 7

DFM, the faultmanagement component uses ICMP by default.

It is designed to do so and you cannot turn this off in the LMS webGUI.

If you turn faultmanagement off I think 99% of the ICMP will be gone.

Cheers,

Michel

Thanks for the reply.

How can I find this IP from DFM and remove it so that Ciscoworks will stop sending the icmp packets?

You can unmanage or remanage device components using the Detailed Device View (cards, interfaces, ports, IP addresses, and so forth). If you unmanage a component, LMS will ignore subsequent events (including traps).

You can check the details here :

http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_lan_management_solution/4.2/user/guide/lms_monitor/mnt-fault.html#wp1586744

-Thanks Vinod **Rating Encourages contributors, and its really free. **

Review Cisco Networking for a $25 gift card