cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1894
Views
0
Helpful
4
Replies

%ASA-6-302015

kp-tkr2014
Level 1
Level 1

Hi ,

 

Here 92.168.2.100 is a LAN device, but I have not opened the  port 6015  port on this machine 

<166>Jan 22 2021 08:59:44: %ASA-6-302015: Built outbound UDP connection 1717941741 for Outside:4.4.4.4/8888 (4.4.4.4/8888) to Inside:192.168.2.100/6015 (3.3.3.3/6015)

So how come the ASA  build a connection 

Thanks

4 Replies 4

...

balaji.bandi
Hall of Fame
Hall of Fame

Can you post full Logs of the session to understand better?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Marvin Rhoads
Hall of Fame
Hall of Fame

When a device communicates to a remote system it dynamically chooses an ephemeral port (n>1024) as the source port in the udp flow or tcp connection. That's what you are seeing as the source port in the ASA log message.

glfhfglkm.png

First i sory i was think that it from inisde not from outisde

Second Which app use with this port 8888?

Let explain what i know about such like this issue,

Some application open other port and this port is exchange in first message.

For example ftp will use one port to connect server to cleint and other port to download.

Here ouside send message to inisde,

Inisde send message with new port 

Here asa inspect these message and open port according to that.

Outisde now can send data to inisde and port open from asa.

So check app for this port and check if you enable inspection in asa for this app 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card